CVE-2026-20122 is a vulnerability in the API of Cisco Catalyst SD-WAN Manager that allows an authenticated, remote attacker to overwrite arbitrary files on the local file system. This flaw is due to improper file handling within the API interface. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and no user interaction, potentially leading to limited impact on confidentiality and integrity. A successful exploit could grant vmanage user privileges. While no public exploit code is available (Metasploit, Nuclei, ExploitDB), Cisco has confirmed active exploitation of similar Catalyst SD-WAN flaws in the wild, and this CVE has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.9.8.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.10, < 20.12.5.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.13, < 20.15.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.16, < 20.18.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
20.12.6CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Catalyst SD-WAN Vulnerabilities
Mar 18, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20122)
Mar 17, 2026Cisco Catalyst SD-WAN Vulnerabilities
Feb 25, 2026