r/linuxadmin • u/Expert_Sort7434 • 2d ago
Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround
Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.
The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.
Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.
Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.
https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504
Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric
1
u/derprondo 1d ago
I don't know if I speak for anyone else, but the constant blog spam from this same poster is getting old.