CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager
Vulnerability ID: CVE-2026-76504
CVSS Score: 9.8
Published: 2026-09-30
CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.
TL;DR
An unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows attackers to perform administrative actions with root-level privileges by exploiting inconsistency in URI hex/percent-encoding handling across web application layers.
⚠️ Exploit Status: ACTIVE
Technical Details
- CWE ID: CWE-177 (Improper Handling of URL Encoding)
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 9.8
- Exploit Status: active
- CISA KEV Listed: Yes (Added September 30, 2026)
- Impact: Complete administrative compromise of SD-WAN management interface
Affected Systems
- Cisco Catalyst SD-WAN Manager (formerly vManage)
-
Catalyst SD-WAN Manager: < 20.9.10.1 (Fixed in:
20.9.10.1) -
Catalyst SD-WAN Manager: >= 20.12.0.0, < 20.12.8.2 (Fixed in:
20.12.8.2) -
Catalyst SD-WAN Manager: >= 20.15.0.0, < 20.15.6.1 (Fixed in:
20.15.6.1) -
Catalyst SD-WAN Manager: >= 20.18.0.0, < 20.18.4.1 (Fixed in:
20.18.4.1) -
Catalyst SD-WAN Manager: >= 26.1.0.0, < 26.1.2.1 (Fixed in:
26.1.2.1) -
Catalyst SD-WAN Manager: >= 26.2.0.0, < 26.2.1 (Fixed in:
26.2.1)
Exploit Details
- ShadowForge Cyber PoC Repository: Exploit verification script and public vulnerability analysis framework detailing target analysis features and command-line execution structures.
Mitigation Strategies
- De-expose Cisco Catalyst SD-WAN Manager management interfaces from the public internet.
- Implement restrictive local network and firewall Access Control Lists (ACLs) to allow traffic only from designated, trusted administrative hosts.
- Enforce authentication protocols at the network perimeter, such as requiring VPN or Multi-Factor authenticated jump servers to access administrative zones.
Remediation Steps:
- Identify the current software generation of all deployed Catalyst SD-WAN Manager instances.
- Cross-reference the running version against the fixed release matrix to determine the correct target firmware path.
- Schedule emergency maintenance windows to deploy the updated software versions.
- Verify that the web interface is inaccessible via paths containing double-escaped or percent-encoded traversal indicators.
References
- Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability
- CISA KEV Catalog Reference for CVE-2026-76504
- CVE-2026-76504 on CVE.org
- NVD Vulnerability Details for CVE-2026-76504
- ShadowForge Cyber Exploit Verification Repository
- ShadowForge Cyber Vulnerability Verification Documentation
Read the full report for CVE-2026-76504 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)