CVE-2026-20262 is an authenticated remote arbitrary file creation and overwrite vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. Improper validation of user-supplied input during file upload processing permits an attacker to send a crafted HTTP request to an affected API endpoint and create or overwrite files on the underlying operating system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a standalone Python proof-of-concept exploit for CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager (vManage), plus a small Bash verification script and supporting documentation. The main exploit file, CVE-2026-20262.py, authenticates to the target web interface via /j_security_check, extracts a CSRF token/session state, and then abuses the AnyConnect profile upload endpoint /dataservice/settings/sdra/anyconnect/profile by placing a path traversal sequence in the multipart filename field. Its core capability is authenticated arbitrary file write on the underlying system. The exploit is operational rather than framework-based: it accepts a target URL, username, password, local file path, and attacker-chosen remote path, then uploads the local file contents to that remote location. The script also includes an optional verification step using /dataservice/file/read?path=... to test whether the file is accessible after upload. The repository documentation describes likely abuse paths such as dropping a malicious WAR into /var/lib/wildfly/standalone/deployments/ for probable server-side code execution, overwriting nginx configuration under /etc/nginx/conf.d/, or writing scripts into privileged directories. Additional files include README.md and NOTAS with vulnerability context, impact, and IOC guidance, an 'Ejecución Básica' usage note with example commands, and 'Script de Verificación Rápida', a Bash helper that queries /dataservice/version to identify potentially vulnerable versions. Overall, this is a real exploit repository centered on authenticated web-based path traversal leading to arbitrary file write, with clear post-exploitation potential but no embedded reverse shell or automated second-stage payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
185 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously fixed Cisco SD-WAN vulnerability mentioned only for comparison with CVE-2026-76504's required fixed releases.
A medium-severity security flaw affecting Cisco Catalyst SD-WAN Manager that is reported as being actively exploited in the wild.
Уязвимость в Cisco Catalyst SD-WAN Manager, связанная с некорректной проверкой пользовательских данных при загрузке файлов, позволяла аутентифицированному пользователю с правами записи создать или перезаписать произвольный файл через уязвимый API, что затем могло привести к повышению привилегий до root и полному захвату системы.
Aktívne zneužívaná zraniteľnosť v Cisco Catalyst SD-WAN Manager webovom používateľskom rozhraní spôsobená nevhodnou kontrolou používateľských vstupov pri nahrávaní súborov. Autentifikovanému útočníkovi s oprávneniami zápisu umožňuje vzdialene vytvárať a prepisovať súbory a následne eskalovať oprávnenia na root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.