Input validation error in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20303
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.
The vulnerability exists due to improper input validation in Catalyst SD-WAN Manager when handling crafted input. A remote user can send specially crafted input to execute arbitrary code, access files outside intended paths, or otherwise compromise the system.
This CVE groups multiple internally discovered issues in the improper input validation class, including path traversal and external path control cases.