cisco-sa-sdwan-webauth-xr8beuuU: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Published Sep 30, 2026
·
Updated

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU

Affected Software

1 affected component
Cisco Catalyst SD-WAN Manager

Event History

Sep 30, 2026
Advisory Published
via Cisco·01:00 PM
Data Sourced
via Cisco·01:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An unauthenticated remote attacker who can send HTTP requests to the affected system's API can attempt exploitation. Successful exploitation provides access to the API with admin-user privileges.

2

What does an attacker need to do to bypass authentication?

The attacker must send a crafted HTTP request that uses URI encoding to bypass an authentication rule protecting a specific API endpoint.

3

Is there a mitigation if updates cannot be installed immediately?

No. The available information states that there are no workarounds that address this vulnerability; Cisco software updates are the stated remediation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203