API Authentication Bypass Vulnerability in Cisco Catalyst SD-WAN Manager
CVE-2026-76504

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
30 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76504?

A vulnerability has been identified in the API session-based authentication management of Cisco Catalyst SD-WAN Manager, which could permit an unauthenticated remote attacker to gain access to the affected system as an admin user. This issue arises from improper URI encoding handling within an HTTP request, allowing the attacker to circumvent authentication measures intended to protect specific API endpoints. By crafting a specially modified HTTP request directed at the API, an attacker can exploit this flaw, potentially leading to unauthorized administrative access.

Affected Version(s)

Cisco Catalyst SD-WAN Manager 18.3.6

Cisco Catalyst SD-WAN Manager 18.3.7

Cisco Catalyst SD-WAN Manager 18.3.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.