SecBoard
Zurück zur CVE-Übersicht

CVE-2026-76504

CRITICAL(9.8)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score65/100 — HOCH
  • CVSS 9.8 — Kritisch
  • Im CISA KEV-Katalog (aktiv ausgenutzt)
  • Weniger als 24 Stunden alt

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

CVSS Score

9.8

Technische Schwere

SecBoard-Einordnung

CVE-2026-76504 betrifft den Cisco Catalyst SD-WAN Manager und ist eine kritische Schwachstelle in der API-Sitzungsauthentifizierungsverwaltung. Sie ermöglicht einem nicht authentifizierten, entfernten Angreifer den Zugriff auf das System mit Administratorrechten. Die Ursache liegt in der unsachgemäßen Handhabung der URI-Kodierung in HTTP-Anfragen, wodurch eine Authentifizierungsregel umgangen wird. Ein erfolgreicher führt zu einem vollständigen Authentifizierungs-Bypass und Administratorzugriff auf die API. Die Schwachstelle ist mit einem von 9.8 (CRITICAL) bewertet und wird aktiv ausgenutzt, wie die Aufnahme in den KEV-Katalog zeigt. Dies unterstreicht die extreme Dringlichkeit der Bedrohung. Aufgrund der aktiven Ausnutzung und der hohen Kritikalität sollten Sicherheitsteams umgehend Maßnahmen ergreifen. Es wird dringend empfohlen, verfügbare Patches oder Mitigationen sofort zu implementieren, um den unautorisierten Administratorzugriff zu verhindern und das Risiko zu minimieren. Eine kontinuierliche Überwachung der betroffenen Systeme ist ebenfalls ratsam.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Erkennung & Indikatoren

Ausnutzung

In den geprüften Quellen nicht genannt

Threat-Hunting-Queries

Sentinel/Defender KQL

let lookback = 1d;
CommonSecurityLog
| where DeviceVendor == "Cisco" and DeviceProduct == "Catalyst SD-WAN Manager"
| where FilePath == "/var/log/nms/containers/service-proxy/serviceproxy-access.log" or FilePath == "/var/log/nms/vmanage-server.log"
| where RawData has "j_security_check" and RawData has_any ("%256a", "%6a")
| where not (SourceIP in ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "127.0.0.1"))
| project TimeGenerated, DeviceName, SourceIP, RawData

Splunk SPL

index=cisco_sdwan_manager (source="/var/log/nms/containers/service-proxy/serviceproxy-access.log" OR source="/var/log/nms/vmanage-server.log") "j_security_check" ("%256a" OR "%6a") NOT (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16 OR src_ip=127.0.0.1)
| table _time, host, src_ip, _raw

Sigma

title: Cisco Catalyst SD-WAN Manager API Auth Bypass
id: 9a1b2c3d-4e5f-6789-0123-456789abcdef
status: experimental
description: Detects attempts to exploit CVE-2026-76504 in Cisco Catalyst SD-WAN Manager by bypassing API authentication.
references:
  - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
logsource:
  product: cisco
  service: sdwan_manager
detection:
  selection:
    - log_file|contains: '/var/log/nms/containers/service-proxy/serviceproxy-access.log'
    - log_file|contains: '/var/log/nms/vmanage-server.log'
  keywords:
    - 'j_security_check'
    - '%6a'
    - '%256a'
  condition: selection
fields:
  - _source_ip
  - _raw
falsepositives:
  - Legitimate URI encoded requests (unlikely for this specific pattern)
level: high

Elastic ES|QL

FROM logs-cisco.sdwan_manager.*
| WHERE (file.path == "/var/log/nms/containers/service-proxy/serviceproxy-access.log" OR file.path == "/var/log/nms/vmanage-server.log")
  AND message : "j_security_check"
  AND (message : "%6a" OR message : "%256a")
  AND NOT (source.ip IN ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "127.0.0.1"))
| SELECT @timestamp, host.name, source.ip, message

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*

Referenzen