Improper Handling of URL Encoding (Hex Encoding) in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-76504
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper handling of URI encoding in HTTP requests within the API session-based authentication management functionality. A remote non-authenticated attacker can send specially crafted requests to the affected API endpoints and obtain access to the system with privileges of the admin user.
Note, the vulnerability is being actively exploited in the wild.