Sceawere
Vulnerability Detail
CVE-2026-76504UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cisco Catalyst SD-WAN Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Cisco
- Product
- Cisco Catalyst SD-WAN Manager
- Attack Type
- Improper Handling of URL Encoding (Hex Encoding)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-30T13:17:20.247Z",
"pubdate": "2026-09-30T13:17:20.247Z",
"executiveSummary": "This vulnerability is an authentication bypass flaw residing within the session-based API management interface of the Cisco Catalyst SD-WAN Manager.\nThe vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to the system with administrative privileges.\nThe core issue stems from improper URI encoding handling during the processing of HTTP requests intended to access restricted API endpoints.\nBy manipulating the request URI, an attacker can circumvent existing authentication enforcement mechanisms, effectively bypassing security controls.\nThe risk implication is critical, as successful exploitation results in full administrative control over the affected SD-WAN Manager, potentially leading to unauthorized configuration changes, data exfiltration, or complete system compromise.\nThe vulnerability is remotely exploitable and does not require pre-existing user credentials, making it a high-priority risk for exposed management interfaces.",
"technicalDetails": "The vulnerability manifests within the API authentication middleware of the Cisco Catalyst SD-WAN Manager, specifically during the normalization and validation phase of incoming HTTP requests.\nThe root cause is an improper handling of URI encoding, which allows an attacker to disguise requests to sensitive API endpoints. When the API gateway or authentication filter parses the URI, specific encoded characters or malformed path structures may be incorrectly interpreted by the security enforcement layer while still being correctly parsed by the application backend.\nExploitation is achieved by submitting a crafted HTTP request where the URI contains specific encoding patterns designed to evade path-matching rules. If the authentication middleware utilizes a blacklist or regex-based pattern matching that fails to account for variations in URI encoding, the filter may incorrectly categorize the request as unauthorized for inspection or, conversely, as not requiring authentication.\nThe attack flow follows these steps: first, the attacker identifies a restricted API endpoint that requires session-based authentication. Second, the attacker crafts an HTTP request modifying the target URI with atypical encoding—such as double-encoding or non-standard percent-encoding—that bypasses the initial security check. Third, the request is forwarded to the backend application logic, which decodes the URI, sees the legitimate, intended destination, and processes the request. Because the security gate was bypassed, the application treats the request as a legitimate authenticated session, granting the attacker the privileges associated with the admin user.\nThe component responsible for this failure is the HTTP request processing pipeline prior to API controller dispatch. This design flaw essentially decouples the authentication-enforcement logic from the final resource routing logic. The impact is severe; by gaining administrative session privileges, an attacker can execute arbitrary API calls, manipulate network configurations, monitor SD-WAN traffic, or compromise subordinate network infrastructure managed by the controller. The vulnerability is network-exposed, assuming the API interface is accessible from the attacker's network segment."
}