Critical Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
Cisco has disclosed a severe authentication bypass flaw in its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, with a CVSS score of 9.8. The vulnerability allows unauthenticated remote attackers to gain administrator-level access to the management API by exploiting improper handling of URI-encoded characters in HTTP requests.
Key Details
- Vulnerability: Improper URL encoding processing in the
j_security_checkendpoint enables attackers to bypass authentication. - Exploitation: A crafted request (e.g.,
POST /%6a_security_check) can grant full admin privileges without credentials or user interaction. - Affected Products: All versions of Cisco Catalyst SD-WAN Manager, regardless of configuration.
- Disclosure Date: September 30, 2026, via advisory cisco-sa-sdwan-webauth-xr8beuuU.
- Weakness Classification: CWE-177 (Improper Handling of URL Encoding).
Impact & Mitigation
Successful exploitation could allow attackers to take control of SD-WAN deployments, posing significant risks to network security. No workaround fully mitigates the issue, making patching critical.
Fixed Releases:
| Release Train | First Fixed Version |
|---|---|
| < 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
Cloud deployments are protected via Cisco-managed mitigations, while on-premises customers must prioritize upgrades. Until patches are applied, Cisco recommends:
- Restricting internet exposure of the management interface.
- Limiting access to trusted hosts and placing SD-WAN components behind firewalls.
- Monitoring logs (
/var/log/nms/containers/service-proxy/serviceproxy-access.logand/var/log/nms/vmanage-server.log) for suspiciousj_security_checkactivity, particularly from unfamiliar IPs or accounts prefixed withviptela-reserved-.
In suspected compromises, administrators should collect an admin-tech package (request admin-tech) before contacting Cisco TAC with CVE-2026-76504 in the case title.
Source: https://gbhackers.com/critical-cisco-sd-wan-vulnerability/
Cisco TPRM report: https://www.rankiteo.com/company/cisco
"id": "cis1790843052",
"linkid": "cisco",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'All users of Cisco Catalyst '
'SD-WAN Manager',
'industry': 'Networking and Cybersecurity',
'location': 'Global',
'name': 'Cisco',
'size': 'Large',
'type': 'Technology Vendor'}],
'attack_vector': 'Remote',
'customer_advisories': 'Customers advised to patch immediately and monitor '
'for suspicious activity',
'date_publicly_disclosed': '2026-09-30',
'description': 'Cisco has disclosed a severe authentication bypass flaw in '
'its Catalyst SD-WAN Manager, tracked as CVE-2026-76504, with '
'a CVSS score of 9.8. The vulnerability allows unauthenticated '
'remote attackers to gain administrator-level access to the '
'management API by exploiting improper handling of URI-encoded '
'characters in HTTP requests.',
'impact': {'operational_impact': 'Full administrative control of SD-WAN '
'deployments',
'systems_affected': 'Cisco Catalyst SD-WAN Manager'},
'post_incident_analysis': {'corrective_actions': 'Fixed releases provided; no '
'workaround fully mitigates '
'the issue',
'root_causes': 'Improper handling of URI-encoded '
'characters in the j_security_check '
'endpoint (CWE-177)'},
'recommendations': ['Apply patches immediately to fixed releases',
'Restrict internet exposure of the management interface',
'Limit access to trusted hosts and place SD-WAN '
'components behind firewalls',
'Monitor logs for suspicious activity',
'Collect admin-tech package in case of suspected '
'compromise'],
'references': [{'date_accessed': '2026-09-30',
'source': 'Cisco Security Advisory',
'url': 'cisco-sa-sdwan-webauth-xr8beuuU'}],
'response': {'communication_strategy': 'Cisco advisory '
'cisco-sa-sdwan-webauth-xr8beuuU',
'containment_measures': ['Restricting internet exposure of the '
'management interface',
'Limiting access to trusted hosts',
'Placing SD-WAN components behind '
'firewalls'],
'enhanced_monitoring': 'Monitoring logs '
'(/var/log/nms/containers/service-proxy/serviceproxy-access.log '
'and /var/log/nms/vmanage-server.log) for '
'suspicious j_security_check activity',
'remediation_measures': 'Patching to fixed releases (20.9.10.1, '
'20.12.8.2, 20.15.6.1, 20.18.4.1, '
'26.1.2.1)'},
'title': 'Critical Authentication Bypass Vulnerability in Cisco Catalyst '
'SD-WAN Manager (CVE-2026-76504)',
'type': 'Authentication Bypass',
'vulnerability_exploited': 'CVE-2026-76504 (Improper handling of URI-encoded '
'characters in HTTP requests)'}