Input validation error in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20303

 

Input validation error in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20303

Published: August 6, 2026


Vulnerability identifier: #VU141019
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20303
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.

The vulnerability exists due to improper input validation in Catalyst SD-WAN Manager when handling crafted input. A remote user can send specially crafted input to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.

This CVE groups multiple internally discovered issues in the improper input validation class, including path traversal and external path control cases.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20303

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2

External References

Related Security Bulletins