Link following in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20310

 

Link following in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20310

Published: August 6, 2026


Vulnerability identifier: #VU141021
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20310
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access or manipulate files through improper link resolution.

The vulnerability exists due to improper link resolution before file access in Catalyst SD-WAN Manager when accessing files through links. A remote user can create or use a crafted link to access or manipulate files through improper link resolution.

This CVE groups multiple internally discovered issues in the improper link resolution before file access class.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20310

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2

External References

Related Security Bulletins