Improper Validation of Specified Quantity in Input in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20313

 

Improper Validation of Specified Quantity in Input in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-20313

Published: August 6, 2026


Vulnerability identifier: #VU141023
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20313
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service or otherwise affect system integrity through malformed quantity values.

The vulnerability exists due to improper validation of specified quantity in input in Catalyst SD-WAN Manager when processing quantity values in input. A remote user can send specially crafted input containing malformed quantity values to cause a denial of service or otherwise affect system integrity through malformed quantity values.

This CVE groups multiple internally discovered issues in the improper validation of specified quantity in input class.


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-20313

Install security update from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2

External References

Related Security Bulletins