Cisco WAN Manager Flaw Opens Admin Door
A critical authentication bypass in Cisco Catalyst SD-WAN Manager let attackers reach an admin API, and the fix requires an upgrade.
A hole in Cisco's SD-WAN management software allowed attackers to slip past an authentication check without proving who they were. Cisco says it has fixed the flaw, but the fix demands action from customers running affected releases.
The affected platform, Cisco Catalyst SD-WAN Manager, is used to configure and operate software-defined network deployments. Because it sits at the control point for large network fleets, a compromise there carries weight far beyond a single device.
How the bypass worked
Cisco said in an advisory that improper handling of URI encoding in HTTP requests enabled attackers to get around an authentication control meant to restrict access to a specific API endpoint. A successful exploit could provide an attacker admin privileges to that API.
The vulnerability, tracked as CVE-2026-76504, carries a critical CVSS score of 9.8. The issue has already been addressed in Cisco SD-WAN Cloud managed by the company, but customers running affected software releases 20.9 and earlier, 20.12, 20.15, 20.18, 26.1, and 26.2 will have to upgrade to their respective patched versions.
Once the management interface is reachable, the effort required to exploit it is minimal. Sakshi Grover, IDC's research director for information and data security, described the attack as remote and unauthenticated.
“The barrier to exploitation is very low once the management interface is reachable,” said Sakshi Grover, IDC’s research director for information and data security. “The vulnerability can be exploited remotely without credentials or user interaction through a crafted HTTP request.”
— Sakshi Grover, IDC’s research director for information and data security
No workaround, only a patch
The bug has no workaround, although Cisco recommends restricting access to the Manager from unsecured networks until it can be upgraded. That advice reflects the difference between an exposed interface and one that is kept off the public internet.
Grover reinforced Cisco's advice, noting that exposure depends on how each organization has deployed the software. An internet-facing management interface is a far more immediate problem than one tucked inside a controlled administrative network.
“While every configuration is affected, the practical exposure is not identical across organizations: an internet-accessible management interface presents a much more immediate risk than one isolated within a tightly controlled administrative network,” Grover said.
— Sakshi Grover, IDC’s research director for information and data security
Why the management layer matters
Compromising the management layer can give an attacker considerably more leverage than having access to an individual edge device. Cisco's official documentation says SD-WAN Manager clusters can support thousands of Cisco Catalyst SD-WAN devices, with supported configurations scaling to as many as 12,500 devices.
That scale is what turns a single authentication bypass into a potential network-wide problem. The effects could reach well beyond the management servers, Grover noted.
“Administrative API access could potentially allow an attacker to understand the network topology, modify templates or policies, weaken segmentation, establish persistence or distribute unauthorized configuration changes across multiple locations,” she said.
— Sakshi Grover, IDC’s research director for information and data security
In other words, an attacker who reaches the API is not merely reading data. They can alter how the network behaves, potentially across many sites at once.
Signs an attacker got in
Cisco has also provided organizations with indicators they can use to check whether attackers have already targeted their SD-WAN Manager instances. The company recommends examining serviceproxy-access.log for requests to the j_security_check endpoint originating from unknown or unauthorized IP addresses.
One example in the advisory uses /%6a_security_check, with the character j in the endpoint represented using URI encoding %6a. That pattern is the same encoding trick that made the bypass possible.
Cisco also recommends checking vmanage-server.log for encoded j_security_check requests involving usernames beginning with viptela-reserved-, which are reserved system service accounts.
Additionally, the company recommended administrators collect admin-tech files from all Catalyst SD-WAN Manager instances, including every node in a cluster and any disaster-recovery deployment, and submit them to Cisco's Technical Assistance Centre for analysis.
What to do after patching
Patching alone may not be enough if an attacker already had access. Grover advised rotating anything that might have been touched during an intrusion.
“Credentials, tokens, keys or certificates should be rotated where the investigation indicates that they may have been accessed or modified,” Grover advised. “Patching closes the vulnerability, but it does not remove persistence or reverse configuration changes that an attacker may already have made.”
— Sakshi Grover, IDC’s research director for information and data security
Cisco advised customers not to wait for the analysis before upgrading. The company recommends moving all affected Managers to a fixed release and then having TAC assess the collected data for indicators of compromise (IOCs). Cisco says the assessment can help determine whether further remediation is necessary.
The numbers behind the risk
- CVSS score: 9.8, rated critical
- Affected releases: 20.9 and earlier, 20.12, 20.15, 20.18, 26.1, and 26.2
- Cluster scale: supported configurations up to 12,500 Cisco Catalyst SD-WAN devices
- Authentication control bypassed via URI encoding in HTTP requests
Those figures show why a management-plane flaw draws attention even when the fix is a software upgrade. The reach of the affected system is large, and the success of an exploit does not require credentials or user interaction.
From severity score to real exposure
Grover warned that a high severity score alone can mask what is actually at stake for a given organization.
“A CVSS 9.8 tells a board that a flaw is severe, but it doesn’t tell them that the exposure may be the whole WAN,” Grover warned. “Incidents like this are what will push organizations to translate technical severity into operational and financial exposure.”
— Sakshi Grover, IDC’s research director for information and data security
That translation is the harder part. A patch closes the vulnerability, but it does not by itself answer whether an attacker already used the bypass, what they changed, or whether they are still present. Those questions are answered by log review, forensic collection, and credential rotation.
What it means for defenders
For organizations running Catalyst SD-WAN Manager, the immediate practical step is to confirm which release they are on and move affected instances to a fixed version. Cisco's guidance to restrict access from unsecured networks is worth applying as a stopgap, especially where the management interface is reachable from the internet.
The deeper lesson is about where network security attention goes. Edge devices often get the scrutiny, but the management layer that configures and controls them can offer an attacker a far broader foothold. A single bypass at that layer can translate into changes across many locations, which is a different order of problem than a compromised branch device.
Defenders should treat the indicators in the advisory as a starting point rather than a complete answer. Checking the named logs for encoded j_security_check requests and reserved service account names can reveal whether the bypass was used, while admin-tech collection and TAC assessment can help determine whether remediation needs to go further. Rotating credentials, tokens, keys, and certificates after an intrusion indication is part of closing the gap that patching alone leaves open.
This article first appeared on Network World.
Sources
- CSO Online Original source
- CVE-2026-76504 Also reporting
- advisory Also reporting
- documentation Also reporting
Continue Reading
England's schools recover faster from cyberattacks
Ofqual survey finds secondary schools reporting fewer incidents and quicker recovery, but training and responsibility gaps persist.
ICO gets new board and a Manchester home
The UK data protection watchdog becomes a corporate body after a leadership scandal and a move from Wilmslow to Manchester.
Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.