SB20260930111 - Authentication bypass in Catalyst SD-WAN Manager API
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Handling of URL Encoding (Hex Encoding) (CVE-ID: CVE-2026-76504) Exploited
CWE-ID: CWE-177 - Improper Handling of URL Encoding (Hex Encoding)
CVSSv4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper handling of URI encoding in HTTP requests within the API session-based authentication management functionality. A remote non-authenticated attacker can send specially crafted requests to the affected API endpoints and obtain access to the system with privileges of the admin user.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.