CVE-2026-20245: Privilege Escalation Vulnerability in Cisco Catalyst SD-WAN Controller EITW

Last Updated: 2026-06-25T15:47:43Z

What’s Happening

As of Friday, June 12th 2026, Cisco updated their initial advisory. It now has a patch available.

Cisco has released an advisory for a High Severity, Privilege Escalation in Cisco Catalyst SD-WAN, CVE-2026-20245. The vulnerability currently has no patch available. It has no workarounds. It has been reported by Cisco as EITW. It does however require netadmin credentials (or the exploitation of vulnerabilities from previous advisories CVE-2026-20182, CVE-2026-20127).

Cisco’s Advisory for the Privilege Escalation Vuln:

Cisco’s Advisories for the Authentication Bypass Vulns from May/February:

CVE-2026-20182 - This vuln has a POC and available metasploit module from Rapid7.

CVE-2026-20127 - This vuln has a POC available from ZeroZenX labs.

IOCs Provided by Cisco

Monitor /var/log/scripts.log for similar log entries. The logs will not determine if an entry is malicious and each entry will need to be reviewed for false positives.

Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0

Mandiant has produced a report on exploitation of this vulnerability.

Actions

Update Cisco SD-WAN to the latest version.

Monitor /var/log/scripts.log for the IOC’s provided by Cisco.

Do not expose Cisco SD-WAN to the public internet. If your instance of Cisco SD-WAN was exposed, we suggest rotating credentials (since netadmin credentials are required if the system is up to date).

Monitor for suspicious password change events in Cisco logs.

Notes

Previous reporting on the Cisco Catalyst SD-WAN vulnerabilities:

https://discourse.ifin.network/t/cve-2026-20182-cisco-catalyst-sd-wan-eitw/457

https://discourse.ifin.network/t/cisco-sd-wan/139

https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/

The POCs for the patched Authentication Bypass Vulnerabilities:

https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/

NIST CVE Entry: