Authentication Bypass Vulnerability (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager Allows Remote Admin Access
What Happened — A newly disclosed vulnerability (CVE‑2026‑76504) in Cisco Catalyst SD‑WAN Manager’s API permits an unauthenticated attacker to bypass the login check by sending a URI‑encoded request. The flaw grants admin‑level access to the manager console and, consequently, to every SD‑WAN device under its control. Exploits have already been observed in the wild.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of weak authentication enforcement on critical management interfaces – a core control objective for any continuous‑control‑assurance program.
- Highlights the need for real‑time monitoring of authentication events and rapid evidence collection to prove that access controls are operating as intended.
- Directly ties to Verisq’s ACCESS_CONTROLS capability, which helps organizations continuously validate authentication mechanisms and produce defensible audit trails.
Who Is Affected – Enterprises and government agencies that deploy Cisco Catalyst SD‑WAN Manager (versions prior to the fixed releases listed). Typical sectors include telecommunications, large‑scale enterprise networks, and public‑sector IT environments.
Recommended Actions
- Upgrade all Cisco Catalyst SD‑WAN Manager instances to the fixed versions (≥ 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1).
- Immediately review authentication logs for anomalous API calls containing URI‑encoded characters.
- Implement continuous monitoring of admin‑level API activity and retain evidence for audit readiness.
Technical Notes – The bypass stems from improper handling of URL encoding (CWE‑177) in the API’s session‑based authentication routine. Attackers exploit the j_security_check endpoint by encoding the letter “j”. No configuration toggle mitigates the issue. Source: CIS Advisory 2026‑105