CVE-2026-76504: Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Other sources
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If mitigations are unavailable, discontinue use of Cisco Catalyst SD-WAN Manager.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No prior authentication or user interaction is required. A remote attacker can target the affected system's API by sending a crafted HTTP request that uses URI encoding to bypass an authentication rule.
What level of access could a successful attacker obtain?
Successful exploitation can bypass authentication and provide access to the API with admin-user privileges. This could expose confidentiality, integrity, and availability of the affected system.
Which systems are exposed?
Cisco Catalyst SD-WAN Manager systems are affected when their API is reachable by a remote attacker. The provided information does not specify affected versions, configurations, or whether the API is exposed by default.