CVE-2026-76504
Overview
This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.
Vulnerability Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Impact
An unauthenticated remote attacker can exploit this vulnerability to gain administrative access to the affected system's API without any user interaction or valid credentials. This enables full control over the system, including the ability to view, modify, or delete configuration data, potentially leading to complete system compromise and disruption of network management operations.
Solution
Cisco has released a security advisory (cisco-sa-sdwan-webauth-xr8beuuU) addressing this issue for Cisco Catalyst SD-WAN Manager. Administrators should apply the patches provided in the advisory promptly. Detailed patch instructions and version-specific updates are available on Cisco’s official security center website to mitigate this authentication bypass vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Catalyst Sd-Wan Manager | All |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Sd-Wan Manager | All |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Sd-Wan Manager | All |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Sd-Wan Manager | All |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Sd-Wan Manager | All |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Sd-Wan Manager | 26.2 |
cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept
EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)
|
ShadowForge-Cyber | 0 | 0 | 2026-09-30 | View |
Threat Feed
7 eventsSighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1613 known victims)
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Active exploitation confirmed — vendor: Cisco, product: Catalyst SD-WAN Manager
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 356 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-76504 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504 |