Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Manager has a security flaw allowing unauthorized attackers to bypass login controls and gain full admin access remotely. This happens because the system mishandles special encoding in web requests, letting attackers trick the system into granting access without proper authentication. Cisco has released updates to fix this issue, but no temporary workaround exists other than restricting network access to trusted sources.

Published 30/9/2026, 1:00:00 pmVerified 1/10/2026, 3:21:44 amRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco Catalyst SD-WAN Manager has a security flaw allowing unauthorized attackers to bypass login controls and gain full admin access remotely. This happens because the system mishandles special encoding in web requests, letting attackers trick the system into granting access without proper authentication. Cisco has released updates to fix this issue, but no temporary workaround exists other than restricting network access to trusted sources.

Technical explanation

How the issue affects the environment

The vulnerability in Cisco Catalyst SD-WAN Manager stems from improper handling of URI encoding during HTTP requests. Specifically, the API's session-based authentication can be bypassed when a crafted HTTP request includes encoded characters (such as %6a instead of 'j') in the URI, allowing the request to evade an authentication rule protecting a critical API endpoint. Successful exploitation grants an unauthenticated remote attacker admin-level privileges to the API, enabling full system control. Cisco addressed this by releasing fixed software versions that correct the URI handling logic. No workaround fully mitigates the risk, though restricting access to trusted networks can reduce exposure.

Operational impact

Why teams should care

Exploitation of this vulnerability allows attackers to fully control Cisco Catalyst SD-WAN Manager systems without authentication, threatening network management integrity, confidentiality, and availability. Since these systems are central to enterprise SD-WAN operations, a breach could disrupt business continuity, compromise sensitive network configurations, and enable further malicious activities. No temporary workaround means organizations must promptly update software or restrict access to avoid potential catastrophic security incidents.

Immediate action

Customers should upgrade affected Cisco Catalyst SD-WAN Manager systems to one of the fixed releases listed, such as 20.9.10.1 or later, to eliminate the vulnerability. This involves applying the official software updates provided by Cisco. Until upgrades are applied, organizations should tightly restrict network access to the system, limiting it to known, trusted hosts and protecting the system behind firewalls and filtering devices.

Affected and fixed releases

Affected versionsVersions earlier than 20.9
Fixed versions20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1, Cloud Hosted Release 20.15.605

Temporary risk reduction

There are no effective workarounds to address this vulnerability. As mitigation, customers should restrict access from untrusted and unsecured networks, such as the internet, limiting system accessibility only to known, trusted hosts on approved ports and protocols. Protecting the system behind firewalls is recommended, but this does not replace the need for upgrading to fixed software.

Evidence and validation checklist

  • Cisco advisory states vulnerability allows unauthenticated remote attacker to gain admin API access due to improper URI encoding handling.
  • No workarounds available; only software updates fix the issue.
  • Exploit involves sending crafted HTTP requests with encoded characters to bypass authentication rules.
  • Multiple fixed software releases available; Cisco Cloud Hosted environment already updated.
  • Cisco PSIRT aware of active exploitation starting September 2026.
  • Customers advised to audit logs for suspicious URI encoded requests indicating exploitation attempts.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Catalyst SD-WAN Manager API Authentication | Advisory | QCS