CVE-2026-76504
September 30, 2026
·
0
Minutes Read

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Advisory
Security Advisory
September 30, 2026
·
0
Minutes Read

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Advisory
Security Advisory
September 30, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-76504) in the API of Cisco Catalyst SD-WAN Manager. An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule and gain administrator-level access to the API.

Cisco has published no workaround. Remediation is to upgrade to a fixed software release.

Affected Systems and/or Applications

  • Cisco Catalyst SD-WAN Manager, all configurations
  • Fixed releases per Cisco:
    • Earlier than 20.9: migrate to a fixed release
    • 20.9: 20.9.10.1
    • 20.12: 20.12.8.2
    • 20.15: 20.15.6.1
    • 20.18: 20.18.4.1
    • 26.1: 26.1.2.1
    • 26.2: 26.2.1
  • Cisco Catalyst SD-WAN Cloud Hosted environments are reported as already remediated by Cisco

Technical Details

Vulnerability Mechanism

CVE-2026-76504 is caused by improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule. No authentication is required, and the only prerequisite is network access to the API of the affected system.

The bypass is not limited to a single character for example the encoding the j of j_security_check as %6a, resulting in /%6a_security_check, and other encoded characters may work as well.

Observed Exploitation Path

Cisco reports active exploitation in September 2026 but does not publish exploitation details beyond the indicators of compromise below. No public proof-of-concept, campaign, or attribution was obtained during this assessment.

Indicators of compromise

  • Audit-log entries for requests to j_security_check containing encoded characters, e.g. POST /%6a_security_check HTTP/1.1, from unauthorized IP addresses
  • Log entries referencing viptela-reserved- system accounts, in the service-proxy and vmanage-server logs.

Mitigation

Limit Exposure

Cisco lists no workaround. As mitigation, restrict internet access to SD-WAN Manager and use firewalls to limit connections to trusted hosts only. Follow the Cisco Catalyst SD-WAN Hardening Guide.

Patch/Upgrade

Upgrade Cisco Catalyst SD-WAN Manager to a fixed release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 or later, according to the release train in use. Releases earlier than 20.9 must migrate to a fixed release. Cisco strongly recommends upgrading.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

References

Related Post