PT-2026-103270 · Cisco · Catalyst Sd-Wan Manager

CVE-2026-76504

·

Published

2026-09-30

·

Updated

2026-10-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager versions prior to 20.9.10.1 Cisco Catalyst SD-WAN Manager versions prior to 20.12.8.2 Cisco Catalyst SD-WAN Manager versions prior to 20.15.6.1 Cisco Catalyst SD-WAN Manager versions prior to 20.18.4.1 Cisco Catalyst SD-WAN Manager versions prior to 26.1.2.1 Cisco Catalyst SD-WAN Manager versions prior to 26.2.1
Description A flaw in the API session-based authentication management of Cisco Catalyst SD-WAN Manager (formerly vManage) allows an unauthenticated remote attacker to gain administrative privileges. The issue is caused by improper handling of URI encoding in HTTP requests, which enables an attacker to bypass authentication rules intended to restrict access to a specific API endpoint. By sending a crafted HTTP request containing URL-encoded variants of the j security check authentication path (such as using %6a for the letter 'j'), an attacker can bypass security checks and access the API as an admin user. This vulnerability has been actively exploited in the wild since September 2026. Successful exploitation grants control over the central management plane, allowing an adversary to modify routing policies, network segmentation rules, and device configurations across the entire SD-WAN environment.
Recommendations Update Cisco Catalyst SD-WAN Manager to version 20.9.10.1 or later. Update Cisco Catalyst SD-WAN Manager to version 20.12.8.2 or later. Update Cisco Catalyst SD-WAN Manager to version 20.15.6.1 or later. Update Cisco Catalyst SD-WAN Manager to version 20.18.4.1 or later. Update Cisco Catalyst SD-WAN Manager to version 26.1.2.1 or later. Update Cisco Catalyst SD-WAN Manager to version 26.2.1 or later. Restrict access to the administrative interface to trusted management networks and approved administrative hosts only.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15713
CVE-2026-76504

Affected Products

Catalyst Sd-Wan Manager