CVE-2026-76504 | Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3 2026-10-1 00:35:46 Author: horizon3.ai(查看原文) 阅读量:4 收藏

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3

CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain API access as the admin user. Cisco assigns it a CVSS 3.1 score of 9.8 and has confirmed active exploitation. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Horizon3.ai’s attack research team reverse engineered the vulnerability.

Technical Details

The vulnerability affects API session-based authentication management. Improper handling of URI encoding in an HTTP request allows an attacker to bypass an authentication rule protecting a specific API endpoint.

An attacker can exploit the issue by sending a crafted request containing an encoded character in the j_security_check path, such as /%6a_security_check. Successful exploitation grants API access as the admin user without requiring valid credentials or user interaction.

By default, the admin user holds the netadmin role, which permits all operations. This access exposes configuration and policy control over the managed SD-WAN fabric. Vulnerable releases are affected regardless of system configuration.

NodeZero® Proactive Security Platform: Rapid Response

A NodeZero Rapid Response test has been developed to safely validate whether this vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.

  • Run the Rapid Response test: Launch from the NodeZero platform to determine whether authentication bypass is possible.
  • Patch immediately: Upgrade to a fixed release and apply Cisco’s recommended access restrictions while arranging the upgrade.
  • Re-run the test: Confirm the vulnerability is no longer exploitable after remediation.

Stop Guessing, Start Proving

Horizon3 website preview featuring NodeZero autonomous security validation

Indicators of Compromise

Cisco recommends reviewing the following logs:

IndicatorTypeDescription
/var/log/nms/containers/service-proxy/serviceproxy-access.logFileReview j_security_check requests from unknown or unauthorized IP addresses, including encoded paths such as /%6a_security_check.
/var/log/nms/vmanage-server.logFileReview related requests from unknown or unauthorized IP addresses, especially those involving usernames beginning with viptela-reserved-.

Encoding %6a is only one example; other encoded characters can trigger the vulnerability. Cisco cautions that these indicators can occur during normal operations, so assess them against expected network activity before concluding that compromise occurred.

Affected versions & patch

Affected

Cisco Catalyst SD-WAN Manager releases in the listed trains that precede their respective first fixed releases are affected. Releases earlier than 20.9 must migrate to a fixed release.

Fixed

Release trainFirst fixed release
Earlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

Cisco has also addressed the vulnerability in Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605. No customer action is required for that service.

Mitigations

Cisco states that no workaround addresses the vulnerability. Until on-premises systems are upgraded, restrict access from untrusted networks, allow only known trusted hosts, and protect SD-WAN control components behind a firewall.

These restrictions are temporary mitigations. Upgrade to an appropriate fixed release to remediate the vulnerability.

Timeline

  • September 30, 2026: Cisco published its security advisory, identified fixed releases, and confirmed active exploitation.
  • September 30, 2026: CISA added CVE-2026-76504 to its KEV catalog.
  • September 30, 2026: Horizon3 alerted affected Rapid Response customers and released the NodeZero Rapid Response test for CVE-2026-76504.

References


文章来源: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-76504/
如有侵权请联系:admin#unsafe.sh