Full Report
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending a specially crafted HTTP request with a URI-encoded character to the Manager's API, which could allow the request to skip an authentication rule intended to restrict access to a specific endpoint. Successful exploitation of this vulnerability could result in an unauthenticated, remote attacker gaining admin-level access to the affected system's API, and by extension the ability to view or modify the configuration of every SD-WAN device that Manager instance controls. This vulnerability affects the product regardless of device configuration; there is no feature toggle or configuration setting that removes the exposure.
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Manager Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-76504
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-697 (Incorrect Comparison)
## Affected Systems
- **Products:** Cisco Catalyst SD-WAN Manager (formerly known as SD-WAN vManage).
- **Versions:** Affects all versions prior to the fixed releases (detailed in Remediation).
- **Configurations:** All deployments are affected regardless of specific feature toggles or configuration settings.
## Vulnerability Description
A flaw exists in the Cisco Catalyst SD-WAN Manager API due to improper handling of URI-encoded characters in HTTP requests. By sending a specially crafted request containing specific encoded characters to the API, an attacker can bypass authentication rules intended to restrict access to management endpoints. Specifically, the flaw allows the request to skip the security check (typically associated with the `j_security_check` path), granting the attacker unauthorized access.
## Exploitation
- **Status:** Exploited in the wild (Confirmed active exploitation).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Ability to view configurations of all managed SD-WAN devices).
- **Integrity:** High (Ability to modify configurations across the entire SD-WAN fabric).
- **Availability:** High (Administrative access allows for disruption of network services).
## Remediation
### Patches
Cisco has released updates to address this vulnerability. Users should migrate to the following versions or later:
- **Cisco Catalyst SD-WAN Manager:** Refer to the official Cisco advisory for specific software train updates (e.g., updates for 20.6.x, 20.9.x, and 20.12.x branches).
### Workarounds
- **No internal workarounds:** There is no configuration setting within the software to disable the vulnerable endpoint.
- **Network Filtering:** Restrict access to the Management Plane/API to trusted internal networks only. Use Access Control Lists (ACLs) to block all unauthorized external traffic to the Manager’s IP addresses.
## Detection
- **Indicators of Compromise (IoC):** Review API and web authentication logs for HTTP requests directed at the `j_security_check` path containing unusual URI-encoded characters (e.g., `%00`, `%2e`, etc.).
- **Forensics:** Before patching, capture administrative diagnostic data and preserve logs if suspicious activity is identified, as the upgrade process may overwrite log files.
- **Scanning:** Utilize vulnerability scanners to identify unpatched Cisco SD-WAN Manager instances.
## References
- **CVE Record:** [https://www.cve.org/CVERecord?id=CVE-2026-76504](hXXps://www.cve.org/CVERecord?id=CVE-2026-76504)
- **Cisco Security Advisory:** [https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU](hXXps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)
- **CIS Advisory:** [https://www.cisecurity.org/advisory/a-vulnerability-in-cisco-catalyst-sd-wan-manager-could-allow-for-authentication-bypass_2026-105](hXXps://www.cisecurity.org/advisory/a-vulnerability-in-cisco-catalyst-sd-wan-manager-could-allow-for-authentication-bypass_2026-105)