A Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication Bypass
MS-ISAC ADVISORY NUMBER:
2026-105DATE(S) ISSUED:
09/30/2026OVERVIEW:
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending a specially crafted HTTP request with a URI-encoded character to the Manager's API, which could allow the request to skip an authentication rule intended to restrict access to a specific endpoint. Successful exploitation of this vulnerability could result in an unauthenticated, remote attacker gaining admin-level access to the affected system's API, and by extension the ability to view or modify the configuration of every SD-WAN device that Manager instance controls. This vulnerability affects the product regardless of device configuration; there is no feature toggle or configuration setting that removes the exposure.
THREAT INTELLIGENCE:
(CVE-2026-76504) has been publicly disclosed and exploited in the wild. Attackers are gaining unauthenticated, admin-level API access by sending an HTTP request with a URI-encoded character (Cisco's indicators of compromise point to encoding the letter "j" within the j_security_check login-handler path), which causes the authentication rule guarding that endpoint to fail to match and allows the request through unauthenticated.
SYSTEMS AFFECTED:
- Cisco Catalyst SD-WAN Manager, versions prior to 20.9.10.1 (releases earlier than 20.9 must migrate to a fixed release)
- Cisco Catalyst SD-WAN Manager, 20.12 versions prior to 20.12.8.2
- Cisco Catalyst SD-WAN Manager, 20.15 versions prior to 20.15.6.1
- Cisco Catalyst SD-WAN Manager, 20.18 versions prior to 20.18.4.1
- Cisco Catalyst SD-WAN Manager, 26.1 versions prior to 26.1.2.1
- Cisco Catalyst SD-WAN Manager, 26.2 versions prior to 26.2.1
RISK:
Government:
Businesses:
Home Users:
TECHNICAL SUMMARY:
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager that could allow for authentication bypass. The vulnerability exists in the API's session-based authentication management, and is due to improper handling of URI encoding in HTTP requests. Details of the vulnerability are as follows:
Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):
- CVE-2026-76504 - An authentication bypass vulnerability (CWE-177: Improper Handling of URL Encoding) in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. An unauthenticated, remote attacker can send a crafted HTTP request containing a URI-encoded character to an API endpoint's login-handler path, causing the authentication rule intended to restrict access to that endpoint to fail to match. The request then reaches the protected endpoint without credentials, granting the attacker admin-user API access. Cisco identified the issue during a Technical Assistance Center (TAC) support case and states its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026.
Successful exploitation of this vulnerability could allow for authentication bypass and administrative API access in the context of the Cisco Catalyst SD-WAN Manager instance. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Accounts that are configured to have fewer rights on the system could be less impacted than those that operate with administrative user rights. In this case, exploitation grants admin-level access directly, so the distinction is limited: an attacker exploiting this vulnerability obtains full administrative control over the SD-WAN Manager API regardless of any account-level restrictions on the system.
RECOMMENDATIONS:
We recommend the following actions be taken:
- Apply the appropriate patches provided by Cisco to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
- Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
- Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
- Safeguard 7.5: Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
- Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
- Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. Configure separate virtual private cloud (VPC) instances to isolate critical cloud systems. (M1030: Network Segmentation)
- Safeguard 12.2: Establish and Maintain a Secure Network Architecture: Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.
- Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
- Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
- Safeguard 5.5: Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
- Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them. (M1016: Vulnerability Scanning)
- Safeguard 18.1: Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
- Safeguard 18.2: Perform Periodic External Penetration Tests: Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
- Safeguard 18.3: Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise's policy for remediation scope and prioritization.
- Since there is no workaround for this vulnerability, treat patching as an emergency deployment outside the normal update cycle, and restrict management-plane/API access to trusted networks in the interim wherever the internet-facing footprint can be reduced.
- Given confirmed active exploitation, review authentication and API access logs for requests to the login-handler path (j_security_check) containing URI-encoded characters, and preserve forensic evidence (e.g., via administrative diagnostic capture) on any exposed instance before upgrading.
