DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-76504: CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager

CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager

Vulnerability ID: CVE-2026-76504
CVSS Score: 9.8
Published: 2026-09-30

CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.

TL;DR

An unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows attackers to perform administrative actions with root-level privileges by exploiting inconsistency in URI hex/percent-encoding handling across web application layers.


⚠️ Exploit Status: ACTIVE

Technical Details

  • CWE ID: CWE-177 (Improper Handling of URL Encoding)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 9.8
  • Exploit Status: active
  • CISA KEV Listed: Yes (Added September 30, 2026)
  • Impact: Complete administrative compromise of SD-WAN management interface

Affected Systems

  • Cisco Catalyst SD-WAN Manager (formerly vManage)
  • Catalyst SD-WAN Manager: < 20.9.10.1 (Fixed in: 20.9.10.1)
  • Catalyst SD-WAN Manager: >= 20.12.0.0, < 20.12.8.2 (Fixed in: 20.12.8.2)
  • Catalyst SD-WAN Manager: >= 20.15.0.0, < 20.15.6.1 (Fixed in: 20.15.6.1)
  • Catalyst SD-WAN Manager: >= 20.18.0.0, < 20.18.4.1 (Fixed in: 20.18.4.1)
  • Catalyst SD-WAN Manager: >= 26.1.0.0, < 26.1.2.1 (Fixed in: 26.1.2.1)
  • Catalyst SD-WAN Manager: >= 26.2.0.0, < 26.2.1 (Fixed in: 26.2.1)

Exploit Details

  • ShadowForge Cyber PoC Repository: Exploit verification script and public vulnerability analysis framework detailing target analysis features and command-line execution structures.

Mitigation Strategies

  • De-expose Cisco Catalyst SD-WAN Manager management interfaces from the public internet.
  • Implement restrictive local network and firewall Access Control Lists (ACLs) to allow traffic only from designated, trusted administrative hosts.
  • Enforce authentication protocols at the network perimeter, such as requiring VPN or Multi-Factor authenticated jump servers to access administrative zones.

Remediation Steps:

  1. Identify the current software generation of all deployed Catalyst SD-WAN Manager instances.
  2. Cross-reference the running version against the fixed release matrix to determine the correct target firmware path.
  3. Schedule emergency maintenance windows to deploy the updated software versions.
  4. Verify that the web interface is inaccessible via paths containing double-escaped or percent-encoded traversal indicators.

References


Read the full report for CVE-2026-76504 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)