Aller au contenu
Toutes les vulnérabilités
CVE-2026-20262KEV

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

Sévérité
Moyenne6,5CVSS 3.1, Moyenne
EPSS
28 %
Publiée
15 juin 2026
Mise à jour
24 juil. 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

Faiblesse : CWE-22

Exploitée activement

Ajoutée au catalogue CISA KEV le 15 juin 2026

Date limite de remédiation fédérale : 29 juin 2026

Action requise : Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Prédiction d’exploitation

Probabilité d’exploitation de 28 % dans les 30 prochains jours (percentile 98 %).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Produits concernés

Patcharo affiche cette vulnérabilité à titre d’information mais ne compare pas encore les versions de ce produit.

  • Cisco Cisco Catalyst SD-WAN Manager · 20.1.12, 19.2.1, 18.4.4, 18.4.5, 20.1.1.1, 20.1.1, 19.3.0, 19.2.2, 19.2.099, 18.3.6, 18.3.7, 19.2.0 et 364 autres

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Cisco (CVE record)
Cisco (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC