Database/Firmware, BMC & network fabric
Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API access
Impact
An authentication rule meant to restrict one API endpoint can be walked past with URI encoding in the request path, so an unauthenticated remote caller reaches the API with admin privileges. SD-WAN Manager is the configuration plane for the WAN edge, so admin there means re-writing routing and policy for every managed device - including the links that carry model artifacts, dataset pulls and remote management traffic in and out of a datacenter. CISA lists this as known exploited, which moves it out of the theoretical column. There is no tenant boundary to hide behind: the attacker needs only reachability to the manager's HTTPS API.
Who can reach it
Any unauthenticated attacker who can send HTTP requests to the SD-WAN Manager API. No credentials, no user interaction. Exposure depends entirely on whether the manager's web/API port is reachable from untrusted networks.
What to do
Upgrade SD-WAN Manager to a fixed release per the Cisco advisory; Cisco lists no workaround for this class of auth-rule bypass. The upgrade is a management-plane maintenance window - the manager restarts and briefly stops accepting configuration pushes, but it does not interrupt data-plane forwarding on the edge devices. Given active exploitation, also restrict the manager's API to management networks and review admin-level API activity and user accounts for changes made before the patch.
References
Related entries
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
- Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds lengthCVE-2026-97413 · Linux kernel RDMA/rtrs-srv (process_read/process_write usr_len validation)Critical
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCVE-2021-21538 · Dell iDRAC9 (Virtual Console / authentication)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.