Cisco Catalyst SD-WAN Manager CVE-2026-76504: URI Encoding Bypasses Authentication for Admin API Access
1. Basic Information Article Title: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability Publisher: Cisco Publication Date: 2026-09-30 Source: Cisco Related Sources: BleepingComputer, CISA KEV c
1. Basic Information
- Article Title: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- Publisher: Cisco
- Publication Date: 2026-09-30
- Source: Cisco
- Related Sources: BleepingComputer, CISA KEV catalog
- Related Malware, Threat Groups, CVEs, Products: CVE-2026-76504, Cisco Catalyst SD-WAN Manager
- Severity: Critical (An API authentication bypass with a CVSS v3.1 base score of 9.8 affects vulnerable versions regardless of configuration. Cisco PSIRT has confirmed active exploitation. Unauthorized API access with admin privileges could affect management of the wider SD-WAN environment.)
2. Overview
Improper handling of URI encoding in Catalyst SD-WAN Manager's API authentication rules allows an unauthenticated remote attacker to send a crafted HTTP request and access the API with the privileges of the admin user. Cisco PSIRT became aware of active exploitation in September 2026 and recommends updating to fixed software. Access restrictions can mitigate exposure, but no workaround addresses the vulnerability itself.
3. Attack Flow
API Authentication Bypass via an Encoded URI
- An unauthenticated remote attacker sends a crafted HTTP request containing URI-encoded characters to the Catalyst SD-WAN Manager API. In Cisco's IOC example, the j in j_security_check is encoded as %6a.
- Improper handling of the encoded URI allows the request to bypass an authentication rule restricting access to a specific API endpoint.
- Successful exploitation gives the attacker access to the API with the privileges of the admin user. Cisco has confirmed active exploitation but has not publicly detailed subsequent operations.
4. Attacker Position and Execution Location
- The attacker must be able to send network requests to the affected Catalyst SD-WAN Manager API. Prior authentication and user interaction are not required.
- The access target is Catalyst SD-WAN Manager's management API. Cisco states that access restrictions have already been applied to Cloud Hosted environments. Separately, Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605 includes the software fix, with no user action required.
5. Victim and Administrator Visibility
Victims
- User-visible symptoms have not been publicly disclosed. Subsequent changes to SD-WAN configurations or traffic paths could cause site connectivity anomalies, but specific instances have not been published.
Administrators
- Review serviceproxy-access.log for successful responses to j_security_check requests from unknown or unauthorized sources. In vmanage-server.log, examine related requests associated with usernames beginning with viptela-reserved-. Correlate these entries with management operations and baseline activity, because Cisco notes that some indicators can also appear during normal operations.
6. Success and Failure Conditions
Success Conditions
- The attacker can reach the API of a vulnerable Catalyst SD-WAN Manager version.
- The affected system processes a crafted URI-encoded request that bypasses the API authentication rule.
Failure Conditions and Risk Reduction
- For customer-managed environments, update to a fixed release in the applicable software branch. Access restrictions are a temporary mitigation and do not resolve the vulnerability itself. Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605 includes the fix, and users do not need to perform the update.
- In on-premises environments, isolate the management plane from untrusted networks such as the internet. Where external access is necessary, restrict it to known, trusted hosts.
- Forward logs to an external server and retain them long enough to investigate activity from the period before patching.
7. Impact Upon Success
- An unauthenticated attacker can access the API with the privileges of the admin user.
- Inference: This access could enable changes to management settings, accounts, or device templates. Specific post-exploitation impacts have not been publicly disclosed.
8. Observable Logs
- Email: Not a direct vector for this vulnerability. Phishing alerts should not be treated as primary evidence.
- Proxy / SWG / DNS: Check reverse proxies or WAFs in front of the management interface for encoded paths, source IPs, and response codes.
- Endpoint / EDR: If process telemetry is available for the management appliance, check for unusual child processes or file modifications associated with web processes. The public disclosure does not establish that subsequent code execution occurred.
- Identity / IdP: Review the creation, modification, and login history of local administrator and operator accounts, together with activity associated with reserved system service accounts.
- SaaS / Cloud: Confirm the remediation status and version of Cisco SD-WAN Cloud (Cisco Managed) through the service GUI's Help function or Cisco TAC. Distinguish the access restrictions applied to Cloud Hosted environments from the software fix in release 20.15.605.
- Network: Check connections to management ports from unknown sources and abnormal outbound traffic from the Manager. Look for URIs such as /%6a_security_check in HTTP logs from devices that terminate or decrypt HTTPS, or in Manager-side access logs. Do not assume these paths are visible in encrypted flow logs alone.
9. Attack Success Determination
Confirmed by Public Information
Cisco PSIRT has confirmed active exploitation. The public disclosure does not identify victim organizations or establish the scope of configuration changes, code execution, or data theft following unauthorized admin API access.
Internal Determination Criteria
- Confirmed Malware Execution or Authentication Success: In this case, the relevant finding is unauthorized API access with admin privileges following authentication bypass. Correlate successful responses to encoded j_security_check requests from unknown or unauthorized sources with evidence of an admin API session or privileged operation associated with a reserved account. An attack request or HTTP 200 response alone is insufficient to confirm successful compromise.
10. Investigation Playbook
- Starting Point: Begin with vulnerable software versions, internet exposure, j_security_check alerts, and CISA KEV notifications.
- Initial Verification: Check software versions, exposure scope, patch application timestamps, log retention, and encoded request paths from unknown sources.
- Endpoint and Server Investigation: Preserve both log files and the admin-tech diagnostic bundle. Investigate changes to accounts, configurations, templates, certificates, and files.
- Authentication and Cloud Investigation: Examine administrators, operators, reserved accounts, and API sessions, and rotate related credentials.
- Tracking Subsequent Activity: Track configuration pushes to managed devices, routing and policy changes, unknown C2 traffic, and data exports.
- Containment: Restrict the management plane to trusted networks and update to fixed versions after preserving evidence. Reissue credentials and certificates if a compromise is confirmed.
- Determination Categories: Record encoded requests, authentication bypasses, administrator actions, and impacts on managed devices by phase.
11. Defense and Detection Ideas
- Single Events: Prioritize HTTP 200 responses to j_security_check requests from unknown or unauthorized sources, especially when correlated with entries associated with usernames beginning with viptela-reserved-.
- Timeline Correlation: Correlate encoded requests, activity associated with reserved accounts, subsequent admin API operations, and configuration pushes to managed devices.
- Threat Hunting: Search raw and normalized request paths for percent-encoded variants of j_security_check, including variants that encode characters other than j. Do not limit detection to %6a.
- Log Limitations: Cisco's IOCs may include false positives, and the absence of logs alone does not rule out a compromise.
- Priority Mitigations: Prioritize patching, management plane isolation, external log retention, and review of the admin-tech diagnostic bundle by Cisco TAC.
12. Facts, Inference, and Hypothesis
Facts
- CVE-2026-76504 results from improper handling of URI encoding in API session-based authentication. A crafted HTTP request can bypass an authentication rule for a specific API endpoint and grant access to the API with the privileges of the admin user.
- Cisco states that affected versions are impacted regardless of configuration, evaluates the vulnerability at CVSS v3.1 9.8, and notes that no workaround exists to resolve the vulnerability itself.
- Cisco PSIRT became aware of active exploitation in September 2026. Its public IOC example uses /%6a_security_check, where %6a encodes j. Cisco notes that the encoded character in the crafted request need not be j, so the example does not cover every variant.
- The first fixed releases for the listed branches are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Deployments running versions earlier than 20.9 must migrate to a fixed release.
Inference
- Management ports exposed to the internet carry particularly high risk, but relying solely on the
%6acharacter from the IOC example will miss variants encoding other characters. - Configuration changes, credential theft, and operations on managed devices following administrator API access are possible, but Cisco has not publicly detailed post-compromise behaviors.
Hypothesis
No additional hypotheses. Unconfirmed items are listed in "Open Questions and Additional Investigation."
13. MITRE ATT&CK Mappings
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | high | Sends crafted HTTP requests to reachable management APIs to bypass authentication rules. |
14. Open Questions and Additional Investigation
- The threat actors behind the active exploitation, the number of victim organizations, and the date of initial exploitation.
- Configuration changes, credential access, and operations performed on managed devices after breaching the admin API.
- URI encoding variants beyond public examples and the complete field structure of exploitation requests.
15. Impact on SOCs and Organizations
Cisco Catalyst SD-WAN Manager manages networks connecting multiple sites, so investigations of an authentication bypass should extend to management configurations, operator accounts, certificates, device templates, and configuration push history. Alongside updating to fixed software, isolate the management plane from the internet. Review externally retained logs for successful j_security_check responses to requests from unknown or unauthorized sources, related activity associated with usernames beginning with viptela-reserved-, and subsequent administrative operations.
16. Summary by Role
- For SOCs: Correlate entries in serviceproxy-access.log and vmanage-server.log with encoded request paths, unknown sources, reserved accounts, and subsequent administrative actions.
- For Administrators: Update to the applicable branch's first fixed release or a later fixed release, restrict management access to trusted hosts, and preserve the admin-tech diagnostic bundle.
- For Users: Remediation and investigation are handled by network administrators. Follow their update and investigation guidance.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.