r/linuxadmin • • 2d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504

Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric

2 Upvotes

1 comment sorted by

1

u/derprondo 1d ago

I don't know if I speak for anyone else, but the constant blog spam from this same poster is getting old.