{"api_version":"1","generated_at":"2026-06-22T14:03:55+00:00","cve":"CVE-2026-20246","urls":{"html":"https://cve.report/CVE-2026-20246","api":"https://cve.report/api/cve/CVE-2026-20246.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-20246","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-20246"},"summary":{"title":"Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability","description":"A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root.","state":"PUBLISHED","assigner":"cisco","published_at":"2026-06-17 17:16:43","updated_at":"2026-06-22 13:24:17"},"problem_types":["CWE-269","CWE-269 Improper Privilege Management"],"metrics":[{"version":"3.1","source":"psirt@cisco.com","type":"Secondary","score":"6","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSSV3_1","score":"6","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU","name":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU","refsource":"psirt@cisco.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-20246","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20246","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.6.0","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.5.6","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.4.12","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.6.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.5.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.5.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.6.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.5.7","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 1.5.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 1.5.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 1.5.6","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.0.0","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.0.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.0.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.1.0","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.1.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.1.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.1.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.2.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.3.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.4.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.4.6","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.9","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.0","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.8.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.0.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.0.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.0.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.0.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.1.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.1.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.1.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.1.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.2.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.2.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.2.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.3.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.3.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.3.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.3.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.3","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.4","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.4.6","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.5","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7.6","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7.9","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 2.7.10","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.5.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.5.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.6.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.6.2","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.7","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.7.1","platforms":[]},{"source":"CNA","vendor":"Cisco","product":"Cisco Umbrella Insights Virtual Appliance","version":"affected 3.8.3","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[{"source":"CNA","title":"","value":"The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.","time":"","lang":"en"}],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"20246","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"umbrella_virtual_appliance","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"20246","cve":"CVE-2026-20246","epss":"0.001040000","percentile":"0.012390000","score_date":"2026-06-21","updated_at":"2026-06-22 00:08:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-20246","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-17T17:15:44.900787Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-06-17T17:17:13.797Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"Cisco Umbrella Insights Virtual Appliance","vendor":"Cisco","versions":[{"status":"affected","version":"2.6.0"},{"status":"affected","version":"2.5.6"},{"status":"affected","version":"2.5"},{"status":"affected","version":"2.4.12"},{"status":"affected","version":"2.7"},{"status":"affected","version":"2.6.2"},{"status":"affected","version":"2.5.5"},{"status":"affected","version":"2.5.4"},{"status":"affected","version":"2.8"},{"status":"affected","version":"2.6.1"},{"status":"affected","version":"2.5.7"},{"status":"affected","version":"1.5.4"},{"status":"affected","version":"1.5.5"},{"status":"affected","version":"1.5.6"},{"status":"affected","version":"2.0.0"},{"status":"affected","version":"2.0.2"},{"status":"affected","version":"2.0.3"},{"status":"affected","version":"2.1.0"},{"status":"affected","version":"2.1.2"},{"status":"affected","version":"2.1.4"},{"status":"affected","version":"2.1.5"},{"status":"affected","version":"2.2"},{"status":"affected","version":"2.2.1"},{"status":"affected","version":"2.3"},{"status":"affected","version":"2.3.1"},{"status":"affected","version":"2.4"},{"status":"affected","version":"2.4.4"},{"status":"affected","version":"2.4.6"},{"status":"affected","version":"2.8.9"},{"status":"affected","version":"3.0"},{"status":"affected","version":"3.1"},{"status":"affected","version":"3.2"},{"status":"affected","version":"2.8.1"},{"status":"affected","version":"2.8.2"},{"status":"affected","version":"2.8.3"},{"status":"affected","version":"2.8.4"},{"status":"affected","version":"2.8.5"},{"status":"affected","version":"3.0.1"},{"status":"affected","version":"3.0.2"},{"status":"affected","version":"3.0.4"},{"status":"affected","version":"3.0.5"},{"status":"affected","version":"3.1.1"},{"status":"affected","version":"3.1.2"},{"status":"affected","version":"3.1.3"},{"status":"affected","version":"3.1.4"},{"status":"affected","version":"3.2.1"},{"status":"affected","version":"3.2.2"},{"status":"affected","version":"3.2.3"},{"status":"affected","version":"3.3"},{"status":"affected","version":"3.3.1"},{"status":"affected","version":"3.3.2"},{"status":"affected","version":"3.3.3"},{"status":"affected","version":"3.3.4"},{"status":"affected","version":"3.4"},{"status":"affected","version":"3.4.1"},{"status":"affected","version":"3.4.2"},{"status":"affected","version":"3.4.3"},{"status":"affected","version":"3.4.4"},{"status":"affected","version":"3.4.5"},{"status":"affected","version":"3.4.6"},{"status":"affected","version":"3.5"},{"status":"affected","version":"2.7.1"},{"status":"affected","version":"2.7.2"},{"status":"affected","version":"2.7.6"},{"status":"affected","version":"2.7.9"},{"status":"affected","version":"2.7.10"},{"status":"affected","version":"3.5.1"},{"status":"affected","version":"3.5.2"},{"status":"affected","version":"3.6.1"},{"status":"affected","version":"3.6.2"},{"status":"affected","version":"3.7"},{"status":"affected","version":"3.7.1"},{"status":"affected","version":"3.8.3"}]}],"descriptions":[{"lang":"en","value":"A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root."}],"exploits":[{"lang":"en","value":"The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"cvssV3_1"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"Improper Privilege Management","lang":"en","type":"cwe"}]}],"providerMetadata":{"dateUpdated":"2026-06-17T16:17:13.708Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"cisco-sa-umbrella-priv-esc-F4wJB7AU","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU"}],"source":{"advisory":"cisco-sa-umbrella-priv-esc-F4wJB7AU","defects":["CSCwt75291"],"discovery":"EXTERNAL"},"title":"Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability"}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2026-20246","datePublished":"2026-06-17T16:17:13.708Z","dateReserved":"2025-10-08T11:59:15.400Z","dateUpdated":"2026-06-17T17:17:13.797Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-17 17:16:43","lastModifiedDate":"2026-06-22 13:24:17","problem_types":["CWE-269","CWE-269 Improper Privilege Management"],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-17T17:15:44.900787Z","id":"CVE-2026-20246","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:umbrella_virtual_appliance:*:*:*:*:*:*:*:*","versionEndExcluding":"3.8.5","matchCriteriaId":"747DFEB4-0F17-4600-8E22-ECB545A12EE8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"20246","Ordinal":"1","Title":"Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerabil","CVE":"CVE-2026-20246","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"20246","Ordinal":"1","NoteData":"A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root.","Type":"Description","Title":"Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerabil"}]}}}