Cisco Warns of Critical Authentication Bypass Flaw in SD-WAN Manager Software
Cisco has issued a warning about a critical authentication bypass flaw in its Catalyst SD-WAN Manager software, formerly known as vManage. The bug, tracked as CVE-2026-76504 with a CVSS score of 9.8, allows an unauthenticated attacker to reach the Manager's API as the admin user via a specially crafted HTTP request.
The flaw is caused by improper handling of URI encoding and can slip past an authentication rule meant to protect a specific API endpoint. Cisco's example in its advisory uses the %6a string in place of the letter j, but any single encoded character will do.
Cisco recommends that customers strongly upgrade to fixed releases, with those on anything earlier than 20.9 required to migrate. The company lists no workarounds for the flaw, which affects SD-WAN Manager regardless of system configuration.