CVE-2026-20224: Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20224?
CVE-2026-20224 is considered a critical severity vulnerability that can allow unauthorized file access.
How do I fix CVE-2026-20224?
To remediate CVE-2026-20224, update Cisco Catalyst SD-WAN Manager to the latest version as specified in Cisco's security advisory.
Who is affected by CVE-2026-20224?
Users of Cisco Catalyst SD-WAN Manager (vManage) are affected by CVE-2026-20224.
What type of vulnerability is CVE-2026-20224?
CVE-2026-20224 is an XML External Entity Injection vulnerability.
Can CVE-2026-20224 be exploited remotely?
Yes, CVE-2026-20224 can be exploited by unauthenticated remote attackers.