Improper Encoding or Escaping of Output in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20245
Published: June 5, 2026 / Updated: June 25, 2026
Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Detailed vulnerability description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the CLI. A local user can upload a specially crafted file and elevate privileges on the target system.
Note, the vulnerability is being actively exploited in the wild.