
Proof-of-concept exploit for CVE-2026-20262 path traversal in Cisco Catalyst SD-WAN Manager, enabling authenticated remote arbitrary file write via unsanitized filename parameter.
CVE-2026-20262 is a Path Traversal (CWE-22) vulnerability in the web interface of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It allows an authenticated attacker with write permissions to create or overwrite any file in the underlying operating system via a crafted HTTP request to the AnyConnect profile upload endpoint.
⚠️ CRITICAL STATUS: The vulnerability is being actively exploited (0-day confirmed by Cisco PSIRT in June 2026). CISA included it in its KEV catalog with a mitigation deadline of June 29, 2026.
| Attribute | Value |
|---|
| CVE | CVE-2026-20262 |
| Product | Cisco Catalyst SD-WAN Manager (vManage) |
| Affected versions | Multiple (see patch table) |
| Patch available | Yes (since June 15, 2026) |
| CVSS Score | 6.5 (Medium) - AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| CWE | 22 (Path Traversal) |
| CISA KEV Status | Active exploitation confirmed (added June 15, 2026) |
| Deadline | June 29, 2026 |
/dataservice/settings/sdra/anyconnect/profile [citation:7]filename parameter is not sanitized, allowing path traversal (../../../../var/lib/wildfly/standalone/deployments/evil.war) [citation:4].war that WildFly automatically deploys, allowing RCE [citation:7][citation:8]According to Cisco [citation:7], the following logs indicate exploitation:
vmanage-server.log (/var/log/nms/):