Full Report
Cisco security advisory (AV26-978)
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Manager API Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-76504
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-288 (Authentication Bypass Using an Alternate Path)
## Affected Systems
- **Products:** Cisco Catalyst SD-WAN Manager (formerly vManage)
- **Versions:**
- Versions prior to 20.9.10.1
- Versions prior to 20.12.8.2
- Versions prior to 20.15.6.1
- Versions prior to 20.18.4.1
- Versions prior to 26.1.2.1
- Versions prior to 26.2.1
- **Configurations:** Systems with the REST API enabled and accessible via the network.
## Vulnerability Description
A vulnerability in the REST API of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to bypass authentication and gain unauthorized access to the application. The flaw exists due to improper validation of authentication tokens when processing requests to specific API endpoints. An attacker can exploit this by sending a specially crafted request to the affected API, allowing them to perform actions with administrative privileges.
## Exploitation
- **Status:** **Exploited in the wild.** Added to CISA KEV Catalog on September 30, 2026.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to configuration data and credentials)
- **Integrity:** High (Ability to modify network configurations and policies)
- **Availability:** High (Potential to disrupt SD-WAN fabric and management services)
## Remediation
### Patches
Cisco has released software updates to address this vulnerability. Users are recommended to migrate to the following fixed releases or later:
- 20.9.10.1
- 20.12.8.2
- 20.15.6.1
- 20.18.4.1
- 26.1.2.1
- 26.2.1
### Workarounds
- **Access Control Lists (ACLs):** Restrict access to the SD-WAN Manager interface and API to trusted management networks only.
- **Disable Unused Services:** If the REST API is not required for operations, ensure it is disabled or strictly firewalled.
## Detection
- **Indicators of Compromise:** Monitor web server logs for unusual status codes (200 OK) on API endpoints originating from unknown or external IP addresses without corresponding successful login events in the audit logs.
- **Detection methods and tools:** Review Cisco SD-WAN Manager Audit Logs for unauthorized configuration changes or user creation. Use CISA’s KEV catalog to cross-reference known malicious patterns.
## References
- Cisco Security Advisory: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- CISA KEV Catalog: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504
- Cisco Publication Listing: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/publicationListing[.]x