In plain language
What this advisory means
Cisco Catalyst SD-WAN Manager has a security weakness in how it processes encoded information in web requests. This flaw allows a remote attacker, without needing any login, to gain admin-level access to the system by exploiting improper handling of URL encoding.
Technical explanation
How the issue affects the environment
The vulnerability in Cisco Catalyst SD-WAN Manager involves improper handling of URI encoding due to a hex encoding flaw. Specifically, an unauthenticated attacker can craft HTTP requests with manipulated URI encodings that bypass normal access controls. This leads to unauthorized admin privilege access on the affected system. The underlying issue is categorized as CWE-177, involving improper handling or comparison of encoded data within HTTP requests.
Operational impact
Why teams should care
An attacker gaining admin privileges remotely without authentication risks full control over the Catalyst SD-WAN Manager device. This can lead to system compromise, interception or manipulation of network traffic managed by the device, and disruption of enterprise WAN operations. The exposure imposes significant operational and security risks for organizations running affected versions of the product.
Immediate action
Organizations should apply mitigations as instructed by Cisco and follow the Cybersecurity and Infrastructure Security Agency's (CISA) Binding Operational Directive 26-04, which prioritizes security updates based on risk. If mitigations are unavailable, discontinuing use of the affected product is advised. Stakeholders must assess each asset's internet exposure, comply with BOD 26-04 patching requirements, and perform forensic triage as mandated.
Affected and fixed releases
Temporary risk reduction
No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.
Evidence and validation checklist
- CISA Known Exploited Vulnerabilities Catalog entry dated 2026-09-30
- Cisco security advisory URL referenced in CISA catalog
- CISA Binding Operational Directive 26-04 guidelines
- Forensic triage requirement per BOD 26-04
Authoritative reference
CISA Known Exploited Vulnerabilities
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
