CVE-2026-20262 — Cisco Catalyst_sd-wan_manager: A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system CVSSv3.1 6.5 (MEDIUM) · EPSS 75th percentile