Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
Release Date: 30th September 2026 (Added 2 October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-76504 is a critical-severity vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
What are the systems affected?
This vulnerability affects Cisco Catalyst SD-WAN Manager, regardless of the system configuration:
- Cisco Catalyst SD-WAN Manager 18.3.6, 18.3.7, 18.3.8, 18.3.6.1, 18.2.0, 18.4.3, 18.4.1, 18.3.3.1, 18.4.0, 18.3.1, 18.3.4, 18.3.1.1, 18.3.5, 18.4.0.1, 18.3.3, 18.3.0 (Affected)
- Cisco Catalyst SD-WAN Manager 17.2.10, 17.2.8, 17.2.6, 17.2.9, 17.2.5, 17.2.7, 17.2.4 (Affected)
What does this mean?
This vulnerability does not require the attacker to possess valid credentials. An attacker only needs network access to a vulnerable Cisco Catalyst SD-WAN Manager instance.
Step 1 - Identify a Reachable SD-WAN Manager
The attacker identifies a Cisco Catalyst SD-WAN Manager system that is accessible from the internet or another reachable network.
Step 2 - Send Crafted Authentication Request
The attacker sends a specifically crafted HTTP request containing URI-encoded characters to a protected authentication endpoint within the SD-WAN Manager API.
Step 3 - Authentication Bypass
Due to improper handling of URI encoding, the system incorrectly processes the request and bypasses an authentication control that should restrict access to authorized users.
Step 4 - Gain Administrator Access
The authentication bypass allows the attacker to gain access to the affected system with administrator-level privileges without providing valid credentials.
Mitigation process?
CERTVU recommends the following:
-
Upgrade Immediately
Upgrade Cisco Catalyst SD-WAN Manager to a fixed software release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1. -
Restrict Internet Exposure
Prevent direct internet access to Cisco Catalyst SD-WAN Manager and allow access only from trusted management networks and authorized IP addresses. -
Deploy Network Filtering Controls
Place SD-WAN control components behind firewalls and enforce strict access-control policies for management interfaces. -
Monitor for Indicators of Compromise
Detect indicators of compromise, including requests to j_security_check and encoded URI variants (for example %6a_security_check). -
Harden Administrative Access
Replace default credentials, enforce strong authentication practices, and apply least-privilege access controls for administrator and operator accounts.
Reference
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2026-76504
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Download advisory (English): Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability