---
id: CVE-2026-20224
title: >-
  A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly
  SD-WAN vManage, could allow an unauthenticated, remote attacker to read
  arbitrary files that are stored in an affected system
summary: >-
  A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly
  SD-WAN vManage, could allow an unauthenticated, remote attacker to read
  arbitrary files that are stored in an affected system. The attacker does not
  need to have va…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-20
published: '2026-05-14'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20224'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R
    label: psirt@cisco.com
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
    label: psirt@cisco.com
tags:
  - nvd
  - exploit-available
epss: 0.01036
epssPercentile: 0.62343
ingestedAt: '2026-06-29T14:58:26.139Z'
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/fevar54/CVE-2026-20224---XXE-Injection-en-Cisco-Catalyst-SD-WAN-Manager
  checkedAt: '2026-09-25T08:20:52.544Z'
exploitAvailable: true
---

## Overview

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.

This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
