News

Catalyst SD-WAN Manager grants unauthenticated admin access

Louis Stowasser
Louis Stowasser
Thursday 1 October 2026
Catalyst SD-WAN Manager grants unauthenticated admin access
Catalyst SD-WAN Manager grants unauthenticated admin access

CVE-2026-76504 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Manager, the control plane administrators use to run a Cisco SD-WAN fabric. This is not a flaw in an individual branch router: Manager centrally provisions edge devices, pushes network policy, manages certificates and software upgrades, and exposes operational visibility across the WAN. An attacker who reaches a vulnerable Manager API needs no account, no password, and no user interaction to obtain the API privileges of the admin user.

That makes the product’s placement matter. Large enterprises, service providers, and branch-heavy organisations use it to operate connectivity across branches, campuses, data centres, and cloud environments. Healthcare, finance, government, retail, manufacturing, energy, logistics, and managed-service environments are among the kinds of deployments where a central WAN management console carries especially broad operational authority.

URI encoding slips past the authentication check

Cisco describes the bug as improper handling of URI encoding in session-based API authentication. Put simply, the server is meant to recognise a protected API endpoint and demand authentication before serving it. A crafted HTTP request can encode a character in its URI such that the authentication rule no longer recognises the path it should protect. The request then reaches the API as though it were the administrator.

Cisco assigns CWE-177, Improper Handling of URL Encoding, and says the problem affects Manager regardless of system configuration. The exact affected source file, function, vulnerable condition, and patch implementation are not public; this is proprietary software and Cisco has published fixed releases rather than a code diff. Its advisory includes indicators involving encoded-character requests to j_security_check, but stresses that encoding any single character may work. Those examples are useful hunting detail, not a runnable exploit.

Exploitation is confirmed; upgrade is the fix

Cisco says its PSIRT learned of active exploitation during September 2026, after the issue was identified while resolving a TAC support case. The attacker, victims, campaign, start date, and number of affected customers have not been publicly identified. CVE-2026-76504 entered CISA’s Known Exploited Vulnerabilities catalogue on September 30, with an October 3 remediation due date reported in the KEV notice. No standalone public proof of concept, Metasploit module, Nuclei template, Exploit-DB entry, or runnable exploit repository had surfaced as of October 1; that does not rule out privately held exploit code.

A patch exists, and there is no workaround that removes the flaw. Upgrade on-premises Manager installations to the first fixed release in their train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Releases earlier than 20.9 require migration to a supported fixed release. Cisco Managed SD-WAN Cloud was fixed in 20.15.605 and requires no customer action.

Until the upgrade is complete, restrict Manager access from unsecured networks and allow required internet access only from known trusted hosts. Collect admin-tech bundles from every Manager, including cluster and disaster-recovery nodes, before upgrading, then use Cisco TAC’s IOC scan; Cisco notes that scan is not a full forensic investigation. Review logs for encoded j_security_check requests and viptela-reserved- usernames, but assess them in context because they can occur normally.

For teams that run this platform, the practical priority is exposure reduction and an expedited upgrade, not trying to tune around the bypass. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, which is useful when a management-plane issue moves from disclosure to active exploitation this quickly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Catalyst SD-WAN Manager grants unauthenticated admin access - SecAlerts