DEV Community

threataft
threataft

Posted on Originally published at threataft.com

Cisco SD-WAN Manager CVE-2026-76504 — CVSS 9.8 Auth Bypass via URI Encoding, Actively Exploited

Cisco has warned of active exploitation of CVE-2026-76504 — a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager.

The mechanic is simple: hex-encode a character in the URI (%6a instead of j), and the authentication rule for j_security_check doesn't match. Request reaches the protected API endpoint. Admin access granted. No credentials required.

What an attacker can do with SD-WAN Manager access:

  • Manipulate network fabric configuration across every branch
  • Reroute or intercept traffic
  • Push malicious configs to connected infrastructure
  • Move laterally via SD-WAN Manager's trusted position

Key facts:

  • CVSS 9.8 — AV:N/AC:L/PR:N/UI:N
  • CWE-288 (Auth Bypass Using Alternate Path)
  • No workarounds — patch is the only fix
  • Cisco has warned of active exploitation

If you run SD-WAN Manager on-prem, check your logs before patching:

serviceproxy-access.log — look for:

vmanage-server.log — look for:

Run request admin-tech on each control component to preserve forensic evidence before upgrading.

Full breakdown with IOCs and mitigation checklist:
https://threataft.com/articles/cisco-catalyst-sd-wan-manager-cve-2026-76504-authentication-bypass

Top comments (0)