Executive Summary

CVE-2026-76504 is an authentication bypass in the API session-based authentication management of Cisco Catalyst SD-WAN Manager, where improper handling of URI encoding in an HTTP request allows a crafted request to defeat a rule intended to restrict a specific API endpoint, yielding admin privileges without credentials. For operators who use SD-WAN Manager to orchestrate connectivity between corporate networks, remote sites, and field assets, a compromise of the management plane is a compromise of the routing and policy fabric that carries OT traffic.

Technical Exposure Breakdown

The defect sits in how the controller normalizes URI encoding before applying its authentication rule set. An attacker encodes characters in the request path so the request does not match the pattern that the authentication filter uses to gate the protected API endpoint, but the backend still resolves the request to that endpoint. This is a classic parser differential: the security control and the application disagree about what resource the request targets. The result is that an unauthenticated, remote attacker reaches an endpoint that executes with the privileges of the admin user.

Per the grounding data, the following Catalyst SD-WAN Manager version ranges are listed as vulnerable: releases up to and including 20.9.10.1, the 20.12 branch through 20.12.8.2, the 20.15 branch through 20.15.6.1, the 20.18 branch through 20.18.4.1, and the 26.1 branch through 26.1.2.1. Patch status is listed as unknown in our source data, so confirm fixed releases directly with the vendor advisory before planning remediation windows.

The attack vector is network reachability to the management API over HTTP. No credentials, no user interaction, and no prior foothold are required. The single precondition that matters is whether an attacker can route a packet to the controller's API. The CVSS score is 9.8, and the vulnerability is flagged in the known exploited vulnerability catalog, which means this is being used, not theorized.

OT Impact and Compliance Risk

SD-WAN Manager is a control point. Admin access to it means an attacker can alter routing policy, VPN topology, access control lists, and the segmentation that separates IT from OT. In many deployments the controller is the authority that decides which site talks to which, and over what path. An attacker with admin can quietly re-route, mirror, or expose traffic between a corporate zone and a process control zone without ever touching a PLC or HMI directly.

This maps badly against the segmentation obligations in IEC 62443 zone and conduit design. If the device enforcing your conduit policy can be taken over by an unauthenticated request, the conduit assurance is nominal. For NERC CIP registered entities, a management-plane controller that influences the Electronic Security Perimeter falls under CIP-005 and CIP-007 scope, and an exploitable bypass is a reportable risk. Pipeline operators under TSA SD-02C and water utilities operating under AWIA 2018 should treat any internet- or IT-reachable instance of this controller as a critical exposure to the network segmentation controls those frameworks require.

Compensating Controls

Do not run active vulnerability scans against the controller or adjacent OT segments to confirm exposure. Aggressive probing of management interfaces and field devices can disrupt services and brick fragile components. Validate exposure from configuration and passive traffic data instead.

Restrict reachability to the SD-WAN Manager API to a dedicated management network and a named allowlist of operator jump hosts. The API should not be reachable from general IT ranges, from vendor VPNs, or from any OT segment. Terminate management access behind a reverse proxy or firewall that performs strict URI normalization and rejects requests containing encoded path traversal and encoded reserved characters against the management hostname.

As a virtual patch concept, deploy a Suricata rule on the conduit in front of the controller that inspects HTTP request paths for percent-encoded sequences targeting the controller's API prefix, and alerts or drops on encoded forms of the protected endpoint. Normalize before matching, and log all matches for incident review. Pair this with monitoring for admin-level API calls originating from unexpected sources, since a successful bypass will present as admin activity with no corresponding authentication event.

Treat any instance in the version ranges above as presumed exposed until the vendor-confirmed fixed release is applied and reachability is constrained.

BreachSpider Intel

BreachSpider tracks known exploited vulnerabilities against industrial and network infrastructure so OT teams can prioritize exposure without scanning live control systems.