Oct 1, 2026·7 min read·11 visits
An unauthenticated remote authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows attackers to perform administrative actions with root-level privileges by exploiting inconsistency in URI hex/percent-encoding handling across web application layers.
CVE-2026-76504 is a critical vulnerability in the web-based management console of Cisco Catalyst SD-WAN Manager. Due to improper normalization and handling of hex/percent-encoded sequences (CWE-177) within incoming request URIs, remote, unauthenticated attackers can bypass administrative authentication controls. Successful exploitation permits full remote administrative command execution on the SD-WAN management plane, threatening the integrity and availability of the managed network fabric.
Cisco Catalyst SD-WAN Manager (formerly vManage) serves as the centralized management and orchestration plane for SD-WAN architectures. It is responsible for provisioning, configuring, and monitoring WAN Edge routers and overall overlay topology. This central role exposes a significant web interface attack surface, which hosts administrative REST APIs for deep orchestration and troubleshooting tasks.
The vulnerability, tracked as CVE-2026-76504, lies in the authentication and authorization middleware responsible for verifying request credentials. By crafting specific request paths containing hex-encoded sequences, an unauthenticated attacker can manipulate the path-routing logic. This causes the security filter to identify a restricted administrative API endpoint as a publicly accessible, non-authenticated resource.
The impact is rated with the maximum CVSSv3.1 score of 9.8 (Critical). Successful exploitation yields complete control of the administrative console. Because the SD-WAN Manager orchestrates the enterprise-wide network topology, compromising this system allows attackers to intercept, redirect, or disrupt transit traffic across the entire enterprise WAN overlay.
The fundamental flaw driving CVE-2026-76504 is a parser differential vulnerability falling under CWE-177: Improper Handling of URL Encoding. The issue arises from mismatched URI parsing logic between the front-end authentication routing filter and the back-end application controller servlet engine.
In standard operation, the authentication filter intercepts incoming HTTP requests and matches the requested path against an access control list (ACL). This ACL defines public endpoints (e.g., login pages or public asset directories) and protected resources (such as /dataservice/ paths). When analyzing the incoming path, the filter checks the string in its raw or partially decoded state. It fails to normalize hex-encoded characters (like %2f for slashes, %252f for double-encoded slashes, or relative path traversal sequences like %2e%2e%2f). Consequently, the filter evaluates a URI containing these encoded values literally and fails to match it against any protected path patterns. This leads the filter to conclude the request is aimed at a public endpoint and waive authentication requirements.
Following the authentication check, the request is forwarded to the backend API router. This component undergoes complete normalization, decoding all hex-encoded variables (e.g., transforming %2f back into a / directory separator). Because the security tier has already flagged the request session as validated or authentication-waived, the backend processes the newly decoded, high-privilege API path directly. The request executes with administrative system privileges because no session credentials were bound to the authenticated-by-default container context.
To understand the implementation flaw, we can analyze the differential behavior between the vulnerable authentication filter and the backend parser logic. In the vulnerable implementation, the application relies on standard servlet URI retrieval helper methods without enforcing strict normalization.
// VULNERABLE COMPONENT: AuthenticationFilter.java
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
throws IOException, ServletException {
HttpServletRequest httpRequest = (HttpServletRequest) request;
// Retrieve the raw request URI without decoding/normalization
String requestURI = httpRequest.getRequestURI();
// The check fails to normalize percent-encoded sequences like %2f or %2e%2e%2f
if (isPublicEndpoint(requestURI)) {
// Request bypasses the authentication validation routine
chain.doFilter(request, response);
return;
}
// Standard session validation occurs here for matched protected endpoints
validateSession(httpRequest);
}// PATCHED COMPONENT: AuthenticationFilter.java
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
throws IOException, ServletException {
HttpServletRequest httpRequest = (HttpServletRequest) request;
// Secure Implementation: Canonicalize, decode, and normalize the URI before evaluation
String normalizedURI = canonicalizeAndNormalizeURI(httpRequest.getRequestURI());
if (isPublicEndpoint(normalizedURI)) {
chain.doFilter(request, response);
return;
}
validateSession(httpRequest);
}
private String canonicalizeAndNormalizeURI(String inputUri) {
if (inputUri == null) return "";
// 1. Perform URL decoding to resolve all percent/hex encodings
String decoded = URLDecoder.decode(inputUri, StandardCharsets.UTF_8);
// 2. Perform secondary decoding to handle double-encoded characters (%252f)
decoded = URLDecoder.decode(decoded, StandardCharsets.UTF_8);
// 3. Normalize relative path traversals (e.g., resolving "/..//" and trailing characters)
return Paths.get(decoded).normalize().toString().replace("\\", "/");
}This patch closes the parsing gap by ensuring both the security check and the backend router operate on the exact same canonical representation of the URI. Relative path segments and double-encoded sequences are resolved before any rule matches run, removing the bypass vector.
Exploitation of CVE-2026-76504 requires minimal configuration and no prior authentication credentials. The attacker crafts a unified HTTP request that routes through the vulnerable gateway.
The target endpoint is typically a sensitive REST API designed to accept CLI execution parameters or system diagnostic requests. Attackers construct the URI using an accepted public path prefix combined with a traversing sequence containing percent-encoded slashes. An example of a normalized logical path mapping is shown below:
https://<SD-WAN-Manager>/public-endpoint/..%2fdataservice/system/device/command
When the front-end routing rule processes the request, the URI is deemed a sub-resource of /public-endpoint and the authentication requirements are waived. Once past the filter, the back-end application decodes the request path, translating %2f back to / and resolving the relative parent directory sequence (..). The resolved request is treated as a high-privilege REST command executing under the administrative system context. The following execution parameters are representative of commands observed during scanning and active abuse:
# Attacker attempts to dump running configuration
curl -k -X POST "https://manager.example.com/public/..%2fdataservice/system/device/command" \
-H "Content-Type: application/json" \
-d '{"command": "show running-config"}'Beyond simple reconnaissance and active credential extraction, threat actors can weaponize this path-traversal flaw to initiate destructive management actions such as executing database commands or executing device-level restarts.
A successful compromise of the Cisco Catalyst SD-WAN Manager represents a complete failure of confidentiality, integrity, and availability within the SD-WAN fabric. Because the management plane controls the control-plane keys, security policies, and WAN Edge router routing tables, an attacker holding administrative access to this system can completely control corporate network paths.
Attackers can leverage this position to inject routing configurations designed to intercept or mirror enterprise site-to-site communication, bypassing transport encryption security guarantees. In addition, access to SD-WAN Manager enables configuration manipulation on all downstream edge devices. This can lock out legitimate administrators, wipe operational configurations, and render physical and virtual networking endpoints offline.
The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities (KEV) Catalog highlights that exploitation is actively occurring in wild scenarios. A three-day binding remediation window was mandated, illustrating the extreme operational risk posed by unpatched management interfaces.
There are no official, viable long-term workarounds for CVE-2026-76504. Organizations must apply official vendor-supplied patches immediately to ensure remediation. Security administrators must identify running software versions and transition them to the corresponding fixed releases.
If immediate patch application is impossible due to change control constraints, temporary mitigations must focus on restricting the physical attack surface:
Network Access Control Lists (ACLs): Restrict access to the Catalyst SD-WAN Manager web-based user interface to verified management IP addresses. External internet exposure must be disabled entirely.
VPN and Bastion Architectures: Place the SD-WAN Manager interface behind an authenticated VPN or bastion system, ensuring that attackers must authenticate at the network edge before interacting with the vulnerable web interface.
Following patch deployment, incident response teams must audit historical log repositories for signs of active exploitation. Specifically, inspect access logs for abnormal requests containing percent-encoded path traversal sequences targeting the HTTP interfaces of the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
Catalyst SD-WAN Manager Cisco | < 20.9.10.1 | 20.9.10.1 |
Catalyst SD-WAN Manager Cisco | >= 20.12.0.0, < 20.12.8.2 | 20.12.8.2 |
Catalyst SD-WAN Manager Cisco | >= 20.15.0.0, < 20.15.6.1 | 20.15.6.1 |
Catalyst SD-WAN Manager Cisco | >= 20.18.0.0, < 20.18.4.1 | 20.18.4.1 |
Catalyst SD-WAN Manager Cisco | >= 26.1.0.0, < 26.1.2.1 | 26.1.2.1 |
Catalyst SD-WAN Manager Cisco | >= 26.2.0.0, < 26.2.1 | 26.2.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-177 (Improper Handling of URL Encoding) |
| Attack Vector | Network (AV:N) |
| CVSS v3.1 Score | 9.8 |
| Exploit Status | active |
| CISA KEV Listed | Yes (Added September 30, 2026) |
| Impact | Complete administrative compromise of SD-WAN management interface |
The software does not properly parse, decode, or normalize URL-encoded/hex-encoded characters, leading to inconsistencies across system endpoints.
An authorization bypass and information leakage vulnerability exists in the SiYuan database module. Unauthenticated users can query the getAttributeViewSearchTarget API endpoint using target block identifiers to extract private content.
An authorization bypass and information disclosure vulnerability in the SiYuan personal knowledge management system before version 3.7.4 allows unauthenticated attackers to query block relationship metadata from password-protected documents.
An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.
A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).
An uncontrolled resource consumption vulnerability in the russh library allows remote authenticated attackers to exhaust server memory (heap) by flooding channel open requests during a stalled key re-exchange (rekeying) process, causing a denial of service via Out-of-Memory (OOM) termination.
A critical memory handling vulnerability exists in the pageant crate, a workspace component of the Rust-based russh SSH client library, during communication with the PuTTY Pageant SSH agent on Windows systems. Prior to version 0.2.3, the library's shared memory parsing logic blindly trusted a peer-controlled, 32-bit big-endian response length field. This allows local attackers running within the same user session to trigger out-of-bounds reads or execute an out-of-memory crash of the client application.