Skip to content

CVE-2026-76504

Cisco Catalyst SD-WAN Manager API authentication bypass allows unauthenticated admin access (CVE-2026-76504)

Critical 9.8 Vendor: Cisco Published

Cisco Catalyst SD-WAN Manager has an API authentication bypass (CVE-2026-76504, CVSS 9.8) that can give an unauthenticated remote attacker admin API access. Cisco PSIRT reports active exploitation; patch and restrict exposure.

What happened

The Cisco Catalyst SD-WAN Manager API mishandles URI encoding in HTTP requests. A crafted request can bypass an authentication rule intended to restrict access to a specific API endpoint. An unauthenticated remote attacker can exploit this to reach the API with the privileges of the admin user. The CVSS vector rates the impact high for confidentiality, integrity and availability (CVSS 3.1, 9.8).

Cisco PSIRT states that, in September 2026, it became aware of active exploitation of this vulnerability. There are no workarounds that address the flaw itself; Cisco's guidance is to upgrade to a fixed software release and, for on-premises deployments, to restrict network access to the system.

Who is affected

The affected product is Cisco Catalyst SD-WAN Manager. The releases listed in Cisco's advisory are 17.2.10, 18.2.0, 18.3.6, 18.3.6.1, 18.3.7, 18.3.8, 18.4.1 and 18.4.3. On-premises deployments are the primary concern; Cisco states that for Cloud Hosted environments the access-restriction mitigation is already deployed. Organisations that expose the management API or management interface to untrusted networks should treat this as urgent.

What to do now

  1. Upgrade to the fixed software release. Cisco states a fix is available and strongly recommends upgrading. Confirm the fixed release for your installed version in the Cisco PSIRT advisory.
  2. Until the upgrade is complete, apply Cisco's mitigation for on-premises deployments: restrict access from unsecured networks such as the internet, place Catalyst SD-WAN control components behind a filtering device or firewall, and allow only known, trusted hosts to send traffic to the system on required ports and protocols. Cisco notes this mitigation is already deployed for Cloud Hosted environments.
  3. Review API session activity and access controls for evidence of unauthorised admin access, particularly if the system has been reachable from the internet.

How to detect it

Monitor API session and authentication logs for admin-level access from internet-facing addresses that are not in your explicit trusted-host rules. Because this vulnerability grants admin API access without credentials, any unexpected new admin session or privileged API action on an on-premises deployment is worth investigating.

Beyond the patch

An unauthenticated route to admin API access is an exposure-management problem first: if the management plane is not reachable from the internet, the practical risk drops sharply. Virtual CISO Services can help you map and reduce that exposed management-plane footprint. Because Cisco PSIRT reports active exploitation and no user interaction is required, Managed Detection & Response is the right safety net for detecting and investigating post-exploitation activity while you patch.

Affected and fixed versions

ProductAffectedFixed in
Cisco Catalyst SD-WAN Manager18.3.6
18.3.7
18.3.8
17.2.10
18.3.6.1
18.2.0
18.4.3
18.4.1
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.