Full Report
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Manager Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-76504
- **CVSS Score:** 9.8 (Critical) - *Based on description of unauthenticated remote admin access*
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) / CWE-115 (Misinterpretation of Input) - *Reflected by improper URI encoding handling*
## Affected Systems
- **Products:** Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
- **Versions:**
- Versions earlier than 20.9
- 20.9
- 20.12
- 20.15
- 20.18
- 26.1
- 26.2
- **Configurations:** All deployments are affected regardless of system configuration.
## Vulnerability Description
The vulnerability exists in the API session-based authentication management component of Cisco Catalyst SD-WAN Manager. It stems from the improper handling of URI encoding within HTTP requests. Specifically, an attacker can use crafted URI-encoded characters (such as `%6a` for the letter "j") to bypass authentication rules intended to restrict access to specific API endpoints. By successfully bypassing these rules, an unauthenticated attacker can gain full administrative privileges on the management dashboard.
## Exploitation
- **Status:** Exploited in the wild (Zero-day)
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to monitor/manage up to 6,000 devices)
- **Integrity:** High (Ability to modify network configurations and escalate privileges)
- **Availability:** High (Potential to disrupt SD-WAN operations across the enterprise)
## Remediation
### Patches
Cisco has released the following fixed software releases:
- **20.9.x:** Upgrade to 20.9.10.1
- **20.12.x:** Upgrade to 20.12.8.2
- **20.15.x:** Upgrade to 20.15.6.1
- **20.18.x:** Upgrade to 20.18.4.1
- **26.1.x:** Upgrade to 26.1.2.1
- **26.2.x:** Upgrade to 26.2.1
- **Earlier than 20.9:** Must migrate to a supported fixed release.
### Workarounds
No specific workarounds were provided in the article; Cisco strongly recommends immediate patching due to active exploitation.
## Detection
- **Indicators of Compromise (IoCs):** Look for malicious requests containing the URI-encoded character **`%6a`** (representing "j").
- **Log Analysis:** Inspect the following log files for entries related to `j_security_check` originating from unknown or unauthorized IP addresses:
- `/var/log/nms/containers/service-proxy/serviceproxy-access.log`
- `/var/log/nms/vmanage-server.log`
- **Action:** If compromise is suspected, collect **admin-tech** files and open a case with Cisco TAC.
## References
- **Vendor Advisory:** [https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)
- **NVD Entry:** [https://nvd.nist.gov/vuln/detail/CVE-2026-76504](https://nvd.nist.gov/vuln/detail/CVE-2026-76504)
- **Technical Guidance:** [https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/225842-remediate-catalyst-sd-wan-security.html](https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/225842-remediate-catalyst-sd-wan-security.html)