CVE-2026-76504 is a critical (CVSS 9.8) flaw in Cisco Catalyst SD-WAN Manager that could let an unauthenticated, remote attacker bypass authentication and use the API with admin user privileges.
What Is It
The flaw is in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. According to the NVD description, the product mishandles URI encoding in HTTP requests. A crafted request can get past an authentication rule meant to restrict access to a specific API endpoint.
An attacker could exploit it by sending a crafted HTTP request to the API of an affected system. If the exploit works, the attacker bypasses authentication and gets API access as the admin user.
Cisco PSIRT classifies the weakness as CWE-177 (Improper Handling of URL Encoding).
Why It Matters
Cisco rates the vulnerability 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H):
- Network-reachable: it can be exploited remotely.
- Low complexity: the attack is not difficult to carry out.
- No privileges or user interaction required.
- High impact on confidentiality, integrity and availability.
SD-WAN Manager is the management plane for a Cisco SD-WAN deployment, so admin-level API access to it is a high-value foothold.
The supplied CISA KEV data contains no entry for this CVE. As of this writing, KEV does not confirm active exploitation. The NVD record is in "Received" status and has not yet been fully analyzed.
What's Vulnerable
The CNA data lists these Cisco Catalyst SD-WAN Manager versions as affected:
- 17.2.x: 17.2.4, 17.2.5, 17.2.6, 17.2.7, 17.2.8, 17.2.9, 17.2.10
- 18.2.x: 18.2.0
- 18.3.x: 18.3.0, 18.3.1, 18.3.1.1, 18.3.3, 18.3.3.1, 18.3.4, 18.3.5, 18.3.6, 18.3.6.1, 18.3.7, 18.3.8
- 18.4.x: 18.4.0, 18.4.0.1, 18.4.1, 18.4.3
The record sets the default status to "unknown," so versions not on this list are not confirmed safe. The NVD record contains no CPE entries yet.
Patch Status
The supplied NVD data does not list fixed versions or workarounds, and there is no CISA KEV required action or due date. Cisco has published a security advisory for this issue (linked below). Administrators running an affected release should check that advisory for fixed software and mitigation guidance. Until they have remediated, they should limit network exposure of the SD-WAN Manager API.