Cisco: Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin

Cisco: Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin

Critical Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

Cisco has disclosed a severe authentication bypass flaw in its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, with a CVSS score of 9.8. The vulnerability allows unauthenticated remote attackers to gain administrator-level access to the management API by exploiting improper handling of URI-encoded characters in HTTP requests.

Key Details

  • Vulnerability: Improper URL encoding processing in the j_security_check endpoint enables attackers to bypass authentication.
  • Exploitation: A crafted request (e.g., POST /%6a_security_check) can grant full admin privileges without credentials or user interaction.
  • Affected Products: All versions of Cisco Catalyst SD-WAN Manager, regardless of configuration.
  • Disclosure Date: September 30, 2026, via advisory cisco-sa-sdwan-webauth-xr8beuuU.
  • Weakness Classification: CWE-177 (Improper Handling of URL Encoding).

Impact & Mitigation

Successful exploitation could allow attackers to take control of SD-WAN deployments, posing significant risks to network security. No workaround fully mitigates the issue, making patching critical.

Fixed Releases:

Release Train First Fixed Version
< 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1

Cloud deployments are protected via Cisco-managed mitigations, while on-premises customers must prioritize upgrades. Until patches are applied, Cisco recommends:

  • Restricting internet exposure of the management interface.
  • Limiting access to trusted hosts and placing SD-WAN components behind firewalls.
  • Monitoring logs (/var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log) for suspicious j_security_check activity, particularly from unfamiliar IPs or accounts prefixed with viptela-reserved-.

In suspected compromises, administrators should collect an admin-tech package (request admin-tech) before contacting Cisco TAC with CVE-2026-76504 in the case title.

Source: https://gbhackers.com/critical-cisco-sd-wan-vulnerability/

Cisco TPRM report: https://www.rankiteo.com/company/cisco

"id": "cis1790843052",
"linkid": "cisco",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'All users of Cisco Catalyst '
                                              'SD-WAN Manager',
                        'industry': 'Networking and Cybersecurity',
                        'location': 'Global',
                        'name': 'Cisco',
                        'size': 'Large',
                        'type': 'Technology Vendor'}],
 'attack_vector': 'Remote',
 'customer_advisories': 'Customers advised to patch immediately and monitor '
                        'for suspicious activity',
 'date_publicly_disclosed': '2026-09-30',
 'description': 'Cisco has disclosed a severe authentication bypass flaw in '
                'its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, with '
                'a CVSS score of 9.8. The vulnerability allows unauthenticated '
                'remote attackers to gain administrator-level access to the '
                'management API by exploiting improper handling of URI-encoded '
                'characters in HTTP requests.',
 'impact': {'operational_impact': 'Full administrative control of SD-WAN '
                                  'deployments',
            'systems_affected': 'Cisco Catalyst SD-WAN Manager'},
 'post_incident_analysis': {'corrective_actions': 'Fixed releases provided; no '
                                                  'workaround fully mitigates '
                                                  'the issue',
                            'root_causes': 'Improper handling of URI-encoded '
                                           'characters in the j_security_check '
                                           'endpoint (CWE-177)'},
 'recommendations': ['Apply patches immediately to fixed releases',
                     'Restrict internet exposure of the management interface',
                     'Limit access to trusted hosts and place SD-WAN '
                     'components behind firewalls',
                     'Monitor logs for suspicious activity',
                     'Collect admin-tech package in case of suspected '
                     'compromise'],
 'references': [{'date_accessed': '2026-09-30',
                 'source': 'Cisco Security Advisory',
                 'url': 'cisco-sa-sdwan-webauth-xr8beuuU'}],
 'response': {'communication_strategy': 'Cisco advisory '
                                        'cisco-sa-sdwan-webauth-xr8beuuU',
              'containment_measures': ['Restricting internet exposure of the '
                                       'management interface',
                                       'Limiting access to trusted hosts',
                                       'Placing SD-WAN components behind '
                                       'firewalls'],
              'enhanced_monitoring': 'Monitoring logs '
                                     '(/var/log/nms/containers/service-proxy/serviceproxy-access.log '
                                     'and /var/log/nms/vmanage-server.log) for '
                                     'suspicious j_security_check activity',
              'remediation_measures': 'Patching to fixed releases (20.9.10.1, '
                                      '20.12.8.2, 20.15.6.1, 20.18.4.1, '
                                      '26.1.2.1)'},
 'title': 'Critical Authentication Bypass Vulnerability in Cisco Catalyst '
          'SD-WAN Manager (CVE-2026-76504)',
 'type': 'Authentication Bypass',
 'vulnerability_exploited': 'CVE-2026-76504 (Improper handling of URI-encoded '
                            'characters in HTTP requests)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.