Cisco SD-WAN’s URL Encoding Bypass Grants Unauthenticated Admin Access. Federal Agencies Have 24 Hours.

Cisco SD-WAN’s URL Encoding Bypass Grants Unauthenticated Admin Access. Federal Agencies Have 24 Hours.

By Heath Callahan
Publication Date: 2026-10-02 18:42:00

Analysis

A single character substitution in a URL path circumvents authentication on the management API that controls entire SD-WAN fabrics. CISA’s deadline is tomorrow.

A critical authentication bypass vulnerability, tracked as CVE-2026-76504, is currently being exploited in the wild against Cisco Catalyst SD-WAN Manager. The vulnerability, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to gain administrative access to the management API. This flaw stems from improper handling of URL/URI encoding, specifically within the j_security_check path.

The exploit mechanism is deceptively simple. By substituting the character ‘j’ with its URI-encoded equivalent, %6a, an attacker can bypass the authentication rules protecting the management API. This single-character manipulation effectively tricks the system into granting access without valid credentials. Because the SD-WAN Manager acts as a centralized control point for up to 6,000 devices, the compromise of…