CVE-2026-76504
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
- Weniger als 24 Stunden alt
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-76504 betrifft den Cisco Catalyst SD-WAN Manager und ist eine kritische Schwachstelle in der API-Sitzungsauthentifizierungsverwaltung. Sie ermöglicht einem nicht authentifizierten, entfernten Angreifer den Zugriff auf das System mit Administratorrechten. Die Ursache liegt in der unsachgemäßen Handhabung der URI-Kodierung in HTTP-Anfragen, wodurch eine Authentifizierungsregel umgangen wird. Ein erfolgreicher Exploit führt zu einem vollständigen Authentifizierungs-Bypass und Administratorzugriff auf die API. Die Schwachstelle ist mit einem CVSS von 9.8 (CRITICAL) bewertet und wird aktiv ausgenutzt, wie die Aufnahme in den CISA KEV-Katalog zeigt. Dies unterstreicht die extreme Dringlichkeit der Bedrohung. Aufgrund der aktiven Ausnutzung und der hohen Kritikalität sollten Sicherheitsteams umgehend Maßnahmen ergreifen. Es wird dringend empfohlen, verfügbare Patches oder Mitigationen sofort zu implementieren, um den unautorisierten Administratorzugriff zu verhindern und das Risiko zu minimieren. Eine kontinuierliche Überwachung der betroffenen Systeme ist ebenfalls ratsam.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Erkennung & Indikatoren
Ausnutzung
In den geprüften Quellen nicht genannt
Threat-Hunting-Queries
Sentinel/Defender KQL
let lookback = 1d;
CommonSecurityLog
| where DeviceVendor == "Cisco" and DeviceProduct == "Catalyst SD-WAN Manager"
| where FilePath == "/var/log/nms/containers/service-proxy/serviceproxy-access.log" or FilePath == "/var/log/nms/vmanage-server.log"
| where RawData has "j_security_check" and RawData has_any ("%256a", "%6a")
| where not (SourceIP in ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "127.0.0.1"))
| project TimeGenerated, DeviceName, SourceIP, RawDataSplunk SPL
index=cisco_sdwan_manager (source="/var/log/nms/containers/service-proxy/serviceproxy-access.log" OR source="/var/log/nms/vmanage-server.log") "j_security_check" ("%256a" OR "%6a") NOT (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16 OR src_ip=127.0.0.1)
| table _time, host, src_ip, _rawSigma
title: Cisco Catalyst SD-WAN Manager API Auth Bypass
id: 9a1b2c3d-4e5f-6789-0123-456789abcdef
status: experimental
description: Detects attempts to exploit CVE-2026-76504 in Cisco Catalyst SD-WAN Manager by bypassing API authentication.
references:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
logsource:
product: cisco
service: sdwan_manager
detection:
selection:
- log_file|contains: '/var/log/nms/containers/service-proxy/serviceproxy-access.log'
- log_file|contains: '/var/log/nms/vmanage-server.log'
keywords:
- 'j_security_check'
- '%6a'
- '%256a'
condition: selection
fields:
- _source_ip
- _raw
falsepositives:
- Legitimate URI encoded requests (unlikely for this specific pattern)
level: highElastic ES|QL
FROM logs-cisco.sdwan_manager.*
| WHERE (file.path == "/var/log/nms/containers/service-proxy/serviceproxy-access.log" OR file.path == "/var/log/nms/vmanage-server.log")
AND message : "j_security_check"
AND (message : "%6a" OR message : "%256a")
AND NOT (source.ip IN ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "127.0.0.1"))
| SELECT @timestamp, host.name, source.ip, messageSecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Betroffene Produkte
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*