Improper Handling of URL Encoding (Hex Encoding) in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-76504

 

Improper Handling of URL Encoding (Hex Encoding) in Catalyst SD-WAN Manager (formerly SD-WAN vManage) - CVE-2026-76504

Published: September 30, 2026


Vulnerability identifier: #VU153026
CSH Severity: Critical
CVSS v4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-76504
CWE-ID: CWE-177
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper handling of URI encoding in HTTP requests within the API session-based authentication management functionality. A remote non-authenticated attacker can send specially crafted requests to the affected API endpoints and obtain access to the system with privileges of the admin user.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Catalyst SD-WAN Manager (formerly SD-WAN vManage)

How to mitigate CVE-2026-76504

Install updates from vendor's website.

Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1

External References

Related Security Bulletins