PT-2026-103270 · Cisco · Catalyst Sd-Wan Manager
CVE-2026-76504
·
Published
2026-09-30
·
Updated
2026-10-03
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Manager versions prior to 20.9.10.1
Cisco Catalyst SD-WAN Manager versions prior to 20.12.8.2
Cisco Catalyst SD-WAN Manager versions prior to 20.15.6.1
Cisco Catalyst SD-WAN Manager versions prior to 20.18.4.1
Cisco Catalyst SD-WAN Manager versions prior to 26.1.2.1
Cisco Catalyst SD-WAN Manager versions prior to 26.2.1
Description
A flaw in the API session-based authentication management of Cisco Catalyst SD-WAN Manager (formerly vManage) allows an unauthenticated remote attacker to gain administrative privileges. The issue is caused by improper handling of URI encoding in HTTP requests, which enables an attacker to bypass authentication rules intended to restrict access to a specific API endpoint. By sending a crafted HTTP request containing URL-encoded variants of the
j security check authentication path (such as using %6a for the letter 'j'), an attacker can bypass security checks and access the API as an admin user. This vulnerability has been actively exploited in the wild since September 2026. Successful exploitation grants control over the central management plane, allowing an adversary to modify routing policies, network segmentation rules, and device configurations across the entire SD-WAN environment.Recommendations
Update Cisco Catalyst SD-WAN Manager to version 20.9.10.1 or later.
Update Cisco Catalyst SD-WAN Manager to version 20.12.8.2 or later.
Update Cisco Catalyst SD-WAN Manager to version 20.15.6.1 or later.
Update Cisco Catalyst SD-WAN Manager to version 20.18.4.1 or later.
Update Cisco Catalyst SD-WAN Manager to version 26.1.2.1 or later.
Update Cisco Catalyst SD-WAN Manager to version 26.2.1 or later.
Restrict access to the administrative interface to trusted management networks and approved administrative hosts only.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catalyst Sd-Wan Manager