One Percent-Encoded Character Makes You Admin: Cisco’s SD-WAN Manager Bypass Was Found in a Support Case

On 30 September 2026 at 13:00 GMT Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU for CVE-2026-76504, an authentication bypass in Cisco Catalyst SD-WAN Manager rated CVSS 3.1 9.8 Critical under CWE-177. An unauthenticated remote attacker sends one crafted HTTP request and gets the API as the admin user. There are no workarounds. Cisco's own advisory states that the PSIRT "became aware of active exploitation of this vulnerability" in September 2026, and CISA added it to the Known Exploited Vulnerabilities catalog the same day with a due date of 3 October 2026 and forensic triage required under BOD 26-04.

Two details make this one worth more than a line in a patch ticket. The bug class is almost comically small. And Cisco says it found it "during the resolution of a Cisco Technical Assistance Center (TAC) support case" — meaning a customer was already in trouble, called support, and the vulnerability fell out of the investigation. The discovery path is the incident report.

The bug: the auth rule and the router disagree about what the URL says

Cisco's description is precise: the flaw is improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule intended to restrict access to a specific API endpoint. The protected endpoint is j_security_check, the Java container login handler. The authentication rule matches the literal path. The downstream handler decodes percent-escapes before dispatching. So a request for /%6a_security_check — %6a being a plain lowercase j — does not match the rule, and still reaches the handler.

Cisco is explicit that the published IOC is only an example: "the vulnerability will allow any one character that is encoded in the request to be used to exploit this." There is no clever escape sequence to blocklist. Any single byte of the path, percent-encoded, produces a string that one layer treats as different and the next layer treats as identical.

This is CWE-177, Improper Handling of URL Encoding — a parser-differential bug, the same shape as the request-smuggling and path-normalization classes that keep resurfacing in front of admin panels. The lesson is architectural rather than textual: an authorization decision made on a raw string before canonicalization is not an authorization decision. The check must run on the same normalized value the dispatcher will use, or the two layers will eventually disagree, and the disagreement is the vulnerability.

What it gets you, and what SD-WAN Manager is

Catalyst SD-WAN Manager (formerly vManage) is the control plane for a fleet — the orchestrator that pushes policy, templates, and configuration to every edge router in the overlay. Admin on that box is not admin on a box; it is authority over the network's forwarding policy. The CVSS vector reflects it exactly: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Network reachable, low complexity, no privileges and no user interaction, total loss of confidentiality, integrity and availability.

Cisco says the vulnerability affects Catalyst SD-WAN Manager regardless of system configuration. There is no feature flag, optional package, or non-default setting that spares you — a sharper exposure profile than last week's Zimbra SNMP command injection, where the attack surface at least required an optional monitoring package.

Fixed releases

From the advisory's fixed-software table:

  • Earlier than 20.9 — no fix on that train; migrate to a fixed release
  • 20.9 → 20.9.10.1  •  20.12 → 20.12.8.2  •  20.15 → 20.15.6.1
  • 20.18 → 20.18.4.1  •  26.1 → 26.1.2.1  •  26.2 → 26.2.1
  • Cisco SD-WAN Cloud (Cisco Managed) — addressed in release 20.15.605; no user action required

For on-premises deployments that cannot patch immediately, Cisco's stated mitigation is network containment, not a code-level fix: restrict access from untrusted networks, place control components behind a filtering device, allow only known trusted hosts on documented ports. Cisco calls that temporary. It is — but it is also the control that would have blunted this bug and the last four like it, which is a reasonable argument for treating "SD-WAN Manager is internet-reachable" as a standing finding rather than a per-CVE one.

Hunt before you patch

Cisco's advisory carries a genuine indicators-of-compromise section, which is rarer than it should be and is the most useful part of the document. Two log sources, both on the Manager itself:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log — look for j_security_check requests from unknown or unauthorized source IPs. Cisco's example entry is a POST /%6a_security_check HTTP/1.1 returning 200. Because any character can be encoded, match on the shape — a percent-escape anywhere in a path that resolves to the login handler — rather than on the literal %6a.
  • /var/log/nms/vmanage-server.log — look for j_security_check entries resolving to users whose names begin with viptela-reserved-. These are documented internal system service accounts; a login mapped to one of them from an external address is the bypass landing.

Cisco notes these indicators can occur during standard operations and must be assessed against your own baseline. If you find something, run request admin-tech on the Manager before changing anything, and open a Severity 3 TAC case with CVE-2026-76504 in the title — preserving the admin-tech bundle first is the difference between an investigation and a guess.

Why this one lands differently

The pattern this site keeps recording is not that infrastructure has bugs. It is the sequencing: exploited first, advisory second, KEV the same day, no workaround, and a patch window measured in hours. NetScaler's zero-days ran ahead of the advisory; MikroTrick took RouterOS pre-auth; WSO2's JWT bypass reached KEV five months after its patch. CVE-2026-76504 adds a three-day BOD 26-04 clock and forensic-triage status on top.

There is also a quieter point worth sitting with as more of this work gets handed to automated discovery. A single-character encoding differential in an auth rule is exactly the kind of defect that Google's own disclosure-trend reporting describes machines getting good at: mechanical, local, pattern-shaped, invisible to a reviewer reading the code for intent. It was found here by a support engineer following a customer's mess backwards. The uncomfortable question is how many of the same differential sit in front of other admin endpoints, in products whose customers have not yet had the incident that makes anyone look.

What to do today

  • Patch to the fixed release for your train. No workaround exists, and the KEV due date was 3 October 2026.
  • Grep both log files before and after patching. Percent-encoded paths resolving to the login handler; viptela-reserved- users logging in from anywhere unexpected. Patching does not evict an attacker who already has admin.
  • Assume post-exploitation if you find a hit. Capture request admin-tech, preserve logs off-box, and treat device credentials, templates, and pushed policy as suspect — an admin on the orchestrator can change the network, not just read it.
  • Take the exposure finding seriously, not just the CVE. If the Manager answers from the internet, that is the condition that converts the next parser differential into an incident. Filter it now while the patch is going out.

Sources: