Cisco SD-WAN Manager hit by zero-day admin access attack

Tags:

Cisco’s SD-WAN management software has been letting some attackers walk through an authentication check without having to prove who they are. The company says it has now fixed the flaw that was allowing it.

The affected platform, Cisco Catalyst SD-WAN Manager, is used to configure and operate software-defined network deployments.

Cisco said in an advisory that improper handling of URI encoding in HTTP requests enabled attackers to get around an authentication control meant to restrict access to a specific API endpoint. A successful exploit could provide an attacker admin privileges to that API.

The vulnerability, tracked as CVE-2026-76504, carries a critical CVSS score of 9.8. The issue has already been addressed in Cisco SD-WAN Cloud managed by the company, but customers running affected software releases 20.9 and earlier, 20.12, 20.15, 20.18, 26.1, and 26.2, will have to upgrade to their respective patched versions.

“The barrier to exploitation is very low once the management interface is reachable,” said Sakshi Grover, IDC’s research director for information and data security. “The vulnerability can be exploited remotely without credentials or user interaction through a crafted HTTP request.”

The bug has no workaround, although Cisco recommends restricting access to the Manager from unsecured networks until it can be upgraded.

“While every configuration is affected, the practical exposure is not identical across organizations: an internet-accessible management interface presents a much more immediate risk than one isolated within a tightly controlled administrative network,” Grover said, reinforcing Cisco’s advice.

Compromising the management layer can give an attacker considerably more leverage than having access to an individual edge device; Cisco’s official documentation says SD-WAN Manager clusters can support thousands of Cisco Catalyst SD-WAN devices, with supported configurations scaling to as many as 12,500 devices.

The effects could reach well beyond the management servers, Grover noted. “Administrative API access could potentially allow an attacker to understand the network topology, modify templates or policies, weaken segmentation, establish persistence or distribute unauthorized configuration changes across multiple locations,” she said.

Clues to hunt for attackers

Cisco has also provided organizations with indicators they can use to check whether attackers have already targeted their SD-WAN Manager instances. The company recommends examining “serviceproxy-access.log” for requests to the “j_security_check” endpoint originating from unknown or unauthorized IP addresses. One example in the advisory uses “/%6a_security_check,” with the character j in the endpoint represented using URI encoding “%6a”.

Cisco also recommends checking “vmanage-server.log” for encoded j_security_check requests involving usernames beginning with viptela-reserved-, which are reserved system service accounts.

Additionally, the company recommended administrators to collect admin-tech files from all Catalyst SD-WAN Manager instances, including every node in a cluster and any disaster-recovery deployment, and submit them to Cisco’s Technical Assistance Centre for analysis.

“Credentials, tokens, keys or certificates should be rotated where the investigation indicates that they may have been accessed or modified,” Grover advised. “Patching closes the vulnerability, but it does not remove persistence or reverse configuration changes that an attacker may already have made.”

Cisco advised customers not to wait for the analysis before upgrading. The company recommends moving all affected Managers to a fixed release and then having TAC assess the collected data for indicators of compromise (IOCs). Cisco says the assessment can help determine whether further remediation is necessary.

“A CVSS 9.8 tells a board that a flaw is severe, but it doesn’t tell them that the exposure may be the whole WAN,” Grover warned. “Incidents like this are what will push organizations to translate technical severity into operational and financial exposure.”

This article first appeared on Network World.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *