Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
Summary
Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-76504) in the API of Cisco Catalyst SD-WAN Manager. An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule and gain administrator-level access to the API.
Cisco has published no workaround. Remediation is to upgrade to a fixed software release.
Affected Systems and/or Applications
- Cisco Catalyst SD-WAN Manager, all configurations
- Fixed releases per Cisco:
- Earlier than 20.9: migrate to a fixed release
- 20.9: 20.9.10.1
- 20.12: 20.12.8.2
- 20.15: 20.15.6.1
- 20.18: 20.18.4.1
- 26.1: 26.1.2.1
- 26.2: 26.2.1
- Cisco Catalyst SD-WAN Cloud Hosted environments are reported as already remediated by Cisco
Technical Details
Vulnerability Mechanism
CVE-2026-76504 is caused by improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule. No authentication is required, and the only prerequisite is network access to the API of the affected system.
The bypass is not limited to a single character for example the encoding the j of j_security_check as %6a, resulting in /%6a_security_check, and other encoded characters may work as well.
Observed Exploitation Path
Cisco reports active exploitation in September 2026 but does not publish exploitation details beyond the indicators of compromise below. No public proof-of-concept, campaign, or attribution was obtained during this assessment.
Indicators of compromise
- Audit-log entries for requests to
j_security_checkcontaining encoded characters, e.g.POST /%6a_security_check HTTP/1.1, from unauthorized IP addresses - Log entries referencing
viptela-reserved-system accounts, in theservice-proxyandvmanage-serverlogs.
Mitigation
Limit Exposure
Cisco lists no workaround. As mitigation, restrict internet access to SD-WAN Manager and use firewalls to limit connections to trusted hosts only. Follow the Cisco Catalyst SD-WAN Hardening Guide.
Patch/Upgrade
Upgrade Cisco Catalyst SD-WAN Manager to a fixed release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 or later, according to the release train in use. Releases earlier than 20.9 must migrate to a fixed release. Cisco strongly recommends upgrading.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.
References
- [1] Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability (published 2026-09-30, retrieved 2026-09-30) - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU - https://security-hub.ncsc.admin.ch/#/posts/13021
- [2] NVD - CVE-2026-76504 (retrieved 2026-09-30) - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-76504
- [3] Cisco Catalyst SD-WAN Hardening Guide - https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide

.avif)





.webp)