Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin
Cisco disclosed CVE-2026-76504, a CVSS 9.8 flaw letting remote attackers gain admin API access on Catalyst SD-WAN Manager.
Cisco disclosed CVE-2026-76504, a CVSS 9.8 authentication-bypass flaw in Catalyst SD-WAN Manager tracked internally as CSCww79570 (CWE-177). Improper handling of URI-encoded characters in HTTP requests can let an unauthenticated remote attacker reach the management API as administrator, regardless of configuration. Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, and 26.1.2.1; earlier than 20.9 must migrate. Cisco SD-WAN Cloud is already mitigated, while on-premises customers are urged to patch, limit exposure, and review logs for suspicious j_security_check requests. The advisory does not report confirmed exploitation.
- CVE-2026-76504 scores CVSS 9.8 and needs no privileges or user interaction.
- URI-encoded characters can bypass session authentication and grant administrator API access.
- Fixed trains include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, and 26.1.2.1.
- Cisco-managed SD-WAN Cloud is already mitigated; on-premises customers should patch urgently.
- Cisco advises checking service-proxy and vManage logs for suspicious j_security_check activity.
Vulnerabilities mentionedAll →
- CVE-2026-765049.82%Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Managerpublished · Cisco Catalyst SD-WAN Manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|
Full article465 words · extracted from gbhackers.com · click to collapse
Cisco has disclosed a critical authentication bypass vulnerability in the Catalyst SD-WAN Manager, which could allow unauthenticated remote attackers to access the management API with administrator privileges.
This vulnerability, tracked as CVE-2026-76504, has a CVSS v3.1 score of 9.8 and affects the Cisco Catalyst SD-WAN Manager regardless of its configuration.
On September 30, 2026, Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU, identifying the issue as a flaw in session-based API authentication management.
The company has assigned the internal bug ID CSCww79570 and classified the weakness under CWE-177 for improper handling of URL encoding.
Cisco SD-WAN Vulnerability
The vulnerability arises from improper processing of URI-encoded characters in HTTP requests. An attacker can send a specially crafted request to the Catalyst SD-WAN Manager API that bypasses an authentication rule intended to protect a specific endpoint.
If successful, this lets an attacker with network access authenticate as the administrator user without valid credentials. Notably, this exploitation requires no privileges or user interaction, which contributes to its critical severity rating.
Cisco’s advisory illustrates the issue with an example request containing an encoded character in the j_security_check endpoint, such as:
POST /%6a_security_check HTTP/1.1
In this case, %6a represents the letter “j.” Cisco emphasizes that this is only one example; encoding a single character in a vulnerable request could allow authentication bypass.
Affected Products and Patches
The Cisco Catalyst SD-WAN Manager is vulnerable across affected software releases, regardless of deployment configuration. Cisco has issued fixed releases and strongly recommends that organizations upgrade rather than rely on temporary controls, as no workaround fully addresses CVE-2026-76504.
The first fixed releases include:
| Cisco Catalyst SD-WAN release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
Cisco SD-WAN Cloud environments are already protected through Cisco-managed mitigations. At the same time, on-premises customers should treat patching as urgent.
Administrators should inspect the `/var/log/nms/containers/service-proxy/serviceproxy-access.log` file for requests involving j_security_check from unfamiliar or unauthorized IP addresses.
They should also review the `/var/log/nms/vmanage-server.log` for j_security_check activity linked to accounts that begin with “viptela-reserved-“, which may indicate an attempted or successful bypass.
Until fixed software can be deployed, Cisco advises on-premises customers to remove internet exposure whenever possible and restrict management-system access to known, trusted hosts. Organizations should also place SD-WAN control components behind firewalls and explicitly filter inbound and outbound traffic.
In the event of a suspected compromise, Cisco recommends collecting an admin-tech package using the `request admin-tech` command before opening a Severity 3 Cisco TAC case that includes CVE-2026-76504 in the title.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.