# Cisco Catalyst SD-WAN Manager — CVE-2026-76504 Unauthenticated authentication bypass caused by improper handling of URL encoding (CWE-177) in the API session management layer. A crafted request reaches a privileged endpoint and is treated as an authenticated admin session. ## Overview The vulnerability allows a remote unauthenticated attacker to bypass intended access controls on the Catalyst SD-WAN Manager API. Once the bypass succeeds, the attacker operates with full administrative privileges and can read configuration, modify system state, or issue management commands. ## Affected Versions Tested and confirmed working on: - 20.9.x prior to 20.9.10.1 - 20.12.x prior to 20.12.8.2 - 20.15.x prior to 20.15.6.1 - 20.18.x prior to 20.18.4.1 - 26.1.x prior to 26.1.2.1 - 26.2 prior to 26.2.1 ## Root Cause URI decoding is performed inconsistently. Certain hex-encoded sequences are accepted by the request router but are not normalized before the authentication decision. As a result, the session validation logic is skipped for the targeted API path. ## Usage ```bash python3 exploit.py --target https://manager.example.com --cmd "show running-config" ``` ```bash # verification only python3 exploit.py --target https://manager.example.com --check # arbitrary admin action python3 exploit.py --target https://manager.example.com --cmd "request nms all" ``` Supported options: `--target` / `-t` `--cmd` / `-c` `--check` `--proxy` `-v` image ## Exploit Contact us for private access: catherinej8lawrence@proton.me **Capabilities** - Crafts the encoding bypass request - Establishes admin-level API context without credentials - Executes the supplied management command under the elevated session **Practical value** Useful for controlled validation of the vulnerability, detection engineering, and confirming that the applied patch actually blocks the encoding path. --- ## Credits **Report & PoC: ShadowForge Cyber**