Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-76504— Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

Quick assessment

Affected
Cisco Cisco Catalyst SD-WAN Manager
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Catalyst SD-WAN Manager 中基于 API 会话的身份验证管理存在一个漏洞,可能允许未经身份验证的远程攻击者以管理员用户权限访问受影响的系统。 该漏洞源于对 HTTP 请求中 URI 编码的处理不当,导致攻击者能够绕过旨在限制特定 API 端点访问的身份验证规则。攻击者可通过向受影响系统的 API 发送精心构造的 HTTP 请求来利用此漏洞。成功利用后,攻击者可绕过身份验证机制,并以管理员用户身份访问该 API。

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76504

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
URL编码处理不恰当(Hex编码)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Catalyst SD-WAN Manager 18.3.6 -

II. Public POCs for CVE-2026-76504

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76504

请登录查看更多情报信息。

Other References for CVE-2026-76504 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76504

No comments yet


Leave a comment