Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20245
Published: June 5, 2026 / Updated: August 31, 2026
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the CLI. A local user can upload a specially crafted file and elevate privileges on the target system.
Note, the vulnerability is being actively exploited in the wild.