CVE-2026-76504 | Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3
CVE-2026-76504 | Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3 CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain API access as the admin user. Cisco assigns it a CVSS 3.1 score of 9.8 and has confirmed active exploitation. CISA added the vulnerability to its Known…
Vulnerabilities mentionedAll →
- CVE-2026-765049.8—Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Managerpublished · Cisco Catalyst SD-WAN Manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76504 | Unauthenticated admin API auth bypass in Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager has a critical flaw in how it manages API session authentication. Improper handling of URI encoding in an HTTP request can bypass an authentication rule that is supposed to restrict a specific API endpoint. An unauthenticated remote attacker can send a crafted HTTP request and gain access to the API with admin privileges, affecting confidentiality, integrity, and availability (CVSS 9.8). Organizations that run Catalyst SD-WAN Manager are affected; the provided data does not list vulnerable or fixed version ranges. No public proof-of-concept is known and the issue is not in CISA's Known Exploited Vulnerabilities catalog. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 20.12.8.2 | r than 20.9 Migrate to a fixed release 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 C |
| ipv4 | 20.15.6.1 | ate to a fixed release 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Cisco has also ad |
| ipv4 | 20.18.4.1 | elease 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Cisco has also addressed the vuln |
| ipv4 | 20.9.10.1 | d release Earlier than 20.9 Migrate to a fixed release 20.9 20.9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2 |
| ipv4 | 26.1.2.1 | 9.10.1 20.12 20.12.8.2 20.15 20.15.6.1 20.18 20.18.4.1 26.1 26.1.2.1 26.2 26.2.1 Cisco has also addressed the vulnerability in C |
Full article535 words · extracted from horizon3.ai · click to collapse
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3
CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain API access as the admin user. Cisco assigns it a CVSS 3.1 score of 9.8 and has confirmed active exploitation. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Horizon3.ai’s attack research team reverse engineered the vulnerability.
Technical Details
The vulnerability affects API session-based authentication management. Improper handling of URI encoding in an HTTP request allows an attacker to bypass an authentication rule protecting a specific API endpoint.
An attacker can exploit the issue by sending a crafted request containing an encoded character in the j_security_check path, such as /%6a_security_check. Successful exploitation grants API access as the admin user without requiring valid credentials or user interaction.
By default, the admin user holds the netadmin role, which permits all operations. This access exposes configuration and policy control over the managed SD-WAN fabric. Vulnerable releases are affected regardless of system configuration.
NodeZero® Proactive Security Platform: Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether this vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
- Run the Rapid Response test: Launch from the NodeZero platform to determine whether authentication bypass is possible.
- Patch immediately: Upgrade to a fixed release and apply Cisco’s recommended access restrictions while arranging the upgrade.
- Re-run the test: Confirm the vulnerability is no longer exploitable after remediation.
Stop Guessing, Start Proving
Indicators of Compromise
Cisco recommends reviewing the following logs:
| Indicator | Type | Description |
/var/log/nms/containers/service-proxy/serviceproxy-access.log | File | Review j_security_check requests from unknown or unauthorized IP addresses, including encoded paths such as /%6a_security_check. |
/var/log/nms/vmanage-server.log | File | Review related requests from unknown or unauthorized IP addresses, especially those involving usernames beginning with viptela-reserved-. |
Encoding %6a is only one example; other encoded characters can trigger the vulnerability. Cisco cautions that these indicators can occur during normal operations, so assess them against expected network activity before concluding that compromise occurred.
Affected versions & patch
Affected
Cisco Catalyst SD-WAN Manager releases in the listed trains that precede their respective first fixed releases are affected. Releases earlier than 20.9 must migrate to a fixed release.
Fixed
| Release train | First fixed release |
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco has also addressed the vulnerability in Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605. No customer action is required for that service.
Mitigations
Cisco states that no workaround addresses the vulnerability. Until on-premises systems are upgraded, restrict access from untrusted networks, allow only known trusted hosts, and protect SD-WAN control components behind a firewall.
These restrictions are temporary mitigations. Upgrade to an appropriate fixed release to remediate the vulnerability.
Timeline
- September 30, 2026: Cisco published its security advisory, identified fixed releases, and confirmed active exploitation.
- September 30, 2026: CISA added CVE-2026-76504 to its KEV catalog.
- September 30, 2026: Horizon3 alerted affected Rapid Response customers and released the NodeZero Rapid Response test for CVE-2026-76504.