Improper privilege management in Cisco Umbrella Virtual Appliance - CVE-2026-20246
Published: June 17, 2026 / Updated: June 17, 2026
Cisco Umbrella Virtual Appliance
Detailed vulnerability description
The vulnerability allows a local privileged user to escalate privileges.
The vulnerability exists due to insufficient validation of user-supplied commands in the vmadmin CLI when processing user-supplied commands. A local privileged user can use certain commands at the CLI to escalate privileges.
A successful exploit could elevate privileges to root.