• PoC PUBLIC

CVE-2026-20303: low-privilege remote code execution in Cisco Cisco Catalyst SD-WAN Controller

An attacker with network access and a low-privilege account can trigger remote code execution against Cisco Catalyst SD-WAN Controller (CVE-2026-20303) by exploiting improper input validation (CWE-20). Affected releases span multiple 17.x, 19.x and 20.x builds, including 17.2.4, 19.3.0, 20.3.6, 20.5.1, 20.6.1, 20.6.2, 20.6.4, 20.7.1, 20.7.2 and 20.9.2; no fixed release is listed in the supplied facts. The flaw requires network access and low privileges but no user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.9CRITICAL
EPSS
0.00487
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high urgency: public exploit code is available, so exposed controllers should be isolated or access restricted immediately while applying vendor guidance.

What is CVE-2026-20303?

An attacker with network access and a low-privilege account can trigger remote code execution against Cisco Catalyst SD-WAN Controller (CVE-2026-20303) by exploiting improper input validation (CWE-20). Affected releases span multiple 17.x, 19.x and 20.x builds, including 17.2.4, 19.3.0, 20.3.6, 20.5.1, 20.6.1, 20.6.2, 20.6.4, 20.7.1, 20.7.2 and 20.9.2; no fixed release is listed in the supplied facts. The flaw requires network access and low privileges but no user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Which versions of Cisco Cisco Catalyst SD-WAN Controller are affected?

BRANCHAFFECTEDFIXED
Cisco Catalyst SD-WAN Controller 20.x20.6.4
Cisco Catalyst SD-WAN Controller 20.x20.9.2
Cisco Catalyst SD-WAN Controller 20.x20.3.6
Cisco Catalyst SD-WAN Controller 20.x20.7.2
Cisco Catalyst SD-WAN Controller 20.x20.7.1
Cisco Catalyst SD-WAN Controller 20.x20.5.1
Cisco Catalyst SD-WAN Controller 20.x20.6.2
Cisco Catalyst SD-WAN Controller 19.x19.3.0
Cisco Catalyst SD-WAN Controller 20.x20.6.1
Cisco Catalyst SD-WAN Controller 17.x17.2.4

Is CVE-2026-20303 being exploited?

Public exploit code is available.

How to fix CVE-2026-20303

  1. Follow Cisco's official mitigation guidance and advisories for the SD-WAN Controller.
  2. Restrict network access to the controller to trusted management networks and VPNs; block internet access where possible.
  3. Harden and rotate low-privilege accounts and credentials; disable or remove unnecessary accounts and services.
  4. Increase logging and monitor controller authentication and command execution for anomalous activity.

Frequently asked questions

Is CVE-2026-20303 being actively exploited?

Public exploit code is available for CVE-2026-20303, indicating a higher risk of active exploitation.

Which Cisco Catalyst SD-WAN Controller versions are affected by CVE-2026-20303?

Multiple 17.x, 19.x and 20.x releases are listed as affected, including 17.2.4, 19.3.0 and several 20.x builds such as 20.6.4 and 20.9.2.

Is there a patch for CVE-2026-20303?

No fixed release is listed in the provided facts; apply mitigations from Cisco and restrict access until a patched release is published.

Does CVE-2026-20303 require authentication?

Yes; the vulnerability requires a low-privilege authenticated account and network access to the Cisco Catalyst SD-WAN Controller.

References