ID:13009 - Exploit for Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20245

 
Main Vulnerability Database Exploits ID:13009 - Exploit for Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20245

ID:13009 - Exploit for Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20245

Published: August 31, 2026


Vulnerability identifier: #VU133402
Vulnerability risk: High
CVE-ID: CVE-2026-20245
CWE-ID: CWE-116
Exploitation vector: Local access
Vulnerable software:
Catalyst SD-WAN Manager (formerly SD-WAN vManage)

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the CLI. A local user can upload a specially crafted file and elevate privileges on the target system.

Note, the vulnerability is being actively exploited in the wild. 


Remediation

Install update from vendor's website.