Knox CVE Database
/
CVE-2026-20245
High
7.8

CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

Added to the CISA KEV catalog:
June 9, 2026

Overview

Cisco Catalyst SD-WAN Manager contains a command injection flaw in its CLI that allows an authenticated local attacker with netadmin privileges to escalate to root. By uploading a specially crafted file, the attacker causes the system to pass unsanitized file contents to a command interpreter, executing arbitrary OS commands. Cisco has observed limited real-world exploitation resulting in configuration changes pushed to downstream edge devices. The Catalyst SD-WAN Controller and Validator share the same vulnerable code path.

Vulnerability details

Affected vendor
Cisco
Affected product
Catalyst SD-WAN Manager
Weakness type (CWE)
CWE-116

The CLI fails to properly encode or escape the contents of a user-supplied file before passing them to a command interpreter, a weakness classified under CWE-116. When file content contains shell metacharacters or command sequences, the interpreter treats them as instructions rather than data. This class of flaw is particularly dangerous in network management software because the CLI operates with elevated system access, and the boundary between data and commands is enforced entirely by the application rather than by OS-level sandboxing.


An attacker who already holds netadmin credentials on the affected system uploads a crafted file through the CLI. The file's contents break out of the expected data context and execute as OS commands under the root account. Cisco has confirmed limited exploitation in the wild, with observed impact including unauthorized configuration changes propagated to SD-WAN edge devices across the fabric. Reaching netadmin access requires either valid credentials or exploitation of a separate, unspecified vulnerability as a precondition.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for unexpected processes spawned from SD-WAN CLI sessions under the netadmin account, particularly any child processes running as root that fall outside the normal management command set for the affected component.
  • Audit configuration change events on SD-WAN edge devices for modifications that lack a corresponding authorized change request or that originate from a control-plane push not initiated by a known administrator session, consistent with Cisco's observed real-world impact.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 23, 2026

Additional hardening

  • Consult the Cisco vendor advisory published May 14, 2026 for fixed software releases for Catalyst SD-WAN Manager, Controller, and Validator; upgrade affected components at the earliest opportunity and verify edge device configurations afterward.
  • Restrict netadmin account access to the minimum set of authorized administrators; enforce multi-factor authentication and review all accounts holding netadmin privileges for signs of unauthorized credential use.
  • Limit CLI access to SD-WAN control components by network segmentation, permitting connections only from dedicated management hosts with known, audited IP addresses rather than from general administrative networks.
  • After upgrading, audit edge device configurations for unauthorized changes pushed from the control plane, as Cisco has observed exploitation resulting in configuration modifications to downstream devices.

Key dates

Published (NVD)
June 4, 2026
Added to CISA KEV
June 9, 2026
Remediation deadline
June 23, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-20245 affect my FedRAMP authorization?

If Cisco Catalyst SD-WAN Manager runs inside your authorization boundary, yes. CVE-2026-20245 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 23, 2026 has already passed. An unpatched KEV in your boundary is an assessor finding under FedRAMP. An overdue one is visible to both your assessor and your sponsoring agency. Remediate now or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-20245?

Knox does not patch your software. Remediating Cisco Catalyst SD-WAN Manager is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with Knox's automated continuous monitoring platform and audit-artifact coverage that support your documentation posture at the next assessment. Applying the fix is yours to own; maintaining compliance while you do it is not something you have to manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-20245. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you a shorter window between disclosure and awareness.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-20245's remediation deadline of June 23, 2026 has passed. What happens now?

If CVE-2026-20245 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing it out now and documenting why the deadline was missed is what keeps your authorization clean and your agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.