GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API access

CVSS 9.8CVE-2026-76504Firmware, BMC & network fabricKnown exploitedcurated

Impact

An authentication rule meant to restrict one API endpoint can be walked past with URI encoding in the request path, so an unauthenticated remote caller reaches the API with admin privileges. SD-WAN Manager is the configuration plane for the WAN edge, so admin there means re-writing routing and policy for every managed device - including the links that carry model artifacts, dataset pulls and remote management traffic in and out of a datacenter. CISA lists this as known exploited, which moves it out of the theoretical column. There is no tenant boundary to hide behind: the attacker needs only reachability to the manager's HTTPS API.

Who can reach it

Any unauthenticated attacker who can send HTTP requests to the SD-WAN Manager API. No credentials, no user interaction. Exposure depends entirely on whether the manager's web/API port is reachable from untrusted networks.

What to do

Upgrade SD-WAN Manager to a fixed release per the Cisco advisory; Cisco lists no workaround for this class of auth-rule bypass. The upgrade is a management-plane maintenance window - the manager restarts and briefly stops accepting configuration pushes, but it does not interrupt data-plane forwarding on the edge devices. Given active exploitation, also restrict the manager's API to management networks and review admin-level API activity and user accounts for changes made before the patch.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.