Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet


Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet

Pierluigi Paganini
June 05, 2026

Cisco warns of CVE-2026-20245 in SD-WAN Manager, a flaw that can lead to root access via file upload command injection; no patch or workaround yet.

Cisco warns of a privilege escalation flaw, tracked as CVE-2026-20245 (CVSS base score of 7.8), in Cisco Catalyst SD-WAN Manager, the platform formerly known as SD-WAN vManage. An authenticated local attacker can trigger the vulnerability to run arbitrary commands as root. No patch is out, and no workaround exists.

The mechanics are straightforward: bad input validation. Although the flaw requires netadmin privileges, attackers can obtain them using stolen credentials or by exploiting previously disclosed vulnerabilities such as CVE-2026-20182 and CVE-2026-20127.

“This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.” reads the advisory. “To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.”

The vulnerability affects Cisco Catalyst SD-WAN Manager across all deployment models, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud deployments, and FedRAMP environments.

Cisco’s interim guidance is surgical: before you upgrade to the fixed release (documented in the May 14 advisory), run request admin-tech on every control component in your SD-WAN deployment. Don’t skip this step.

“If the logs show indicators of compromise and the system is confirmed to be compromised, applying the software update alone will not resolve the vulnerability.” concludes the advisory. “In such cases, follow the specific remediation steps that will be provided by the Cisco Technical Assistance Center (TAC) to help secure the system.”

The researchers pointed out that patching over a compromised system doesn’t clean it. It just gives you a patched, compromised system.

For detection, check the scripts.log file at /var/log/ for entries referencing vconfd_script_upload_tenant_list.sh. Cisco warns these are legitimate commands too, so you’ll need to compare them against your baseline to tell benign from malicious. If you’re unsure whether your environment is clean, open a TAC case and bring the admin-tech file with you.

In February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Cisco SD-WAN flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2022-20775 Cisco Catalyst SD-WAN Path Traversal Vulnerability
  • CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cisco SD-WAN)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Plex’s Remote Watch Pass is getting a 50% price hike starting June 1, 2026. Plex introduced the Remote Watch Pass in April 2025 as a cheaper alternative to the Plex Pass. Remote Watch Pass allows users to remotely stream from any Plex Media Server that a user has access to.

Remote Watch Pass essentially gives a user access to remote streaming, but that’s about it. It’s ideal for those who only want to use Plex as a viewer who is accessing someone else’s Plex Media Server. Core features and benefits of a Plex Server are locked behind the Plex Pass subscription instead.

Currently, Remote Watch Pass is available for $1.99 per month, and its annual plan is for $19.99. This has been the introductory price since the April launch last year. It’s now getting a price bump, and it’s a considerable increase.

A Reddit user received the price increase information via email and shared it with other users. The email said, “We hope you’re enjoying your Remote Watch Pass and the ability to stream personal media wherever you go. We wanted to let you know that your Remote Watch Pass introductory pricing is ending on June 1st, 2026. Beginning on June 1st, 2026, renewals for your subscription will be at the normal subscription price.”


A phone with the Plex logo and a laptop beside it with the Plex home screen.


Plex Pass Lifetime Memberships Double in Price Next Month, so Sign Up Now

Plex Pass will experience a major price hike on April 29th. Grab a lifetime membership today to avoid the price hike.

Plex Remote Watch Pass will increase from $1.99/month to $2.99/month, and its annual plan will increase from $19.99 to $29.99/year. Given that users have enjoyed the introductory price for over a year, the price increase was expected to come at some point.

Users who own a server and have a Plex Pass can share their benefits and let other users stream from their server for free. That’s another reason why Plex Pass continues to be the popular choice for Plex users. You can also get a Plex Pass lifetime subscription, but there’s no such option for Remote Watch Pass yet.

Sharing thoughts in the same Reddit post, there’s a majority of Plex users who feel that the Plex Pass lifetime pass, which is available for $249.99, is an increasingly attractive option. “Best thing I ever did was buy the lifetime pass,” shared one user.

However, for those who only want the Plex experience as a viewer on someone else’s server, the Remote Watch Pass is the cheaper option when compared to the standard pricing of a Plex Pass subscription, which is available for $6.99 per month, or $69.99 for a year.

Source: Reddit

Compatibility

Windows, Linux, macOS, Android, iOS, and various other devices

Free Trial Period

Free account available




Source link