CVE-2026-76504

Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504)

Initial Access Privilege Escalation Last updated:

Detects exploitation attempts against CVE-2026-76504, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The flaw (CWE-177, improper handling of hex/percent-encoded characters in URL request paths) allows a remote, unauthenticated attacker to bypass web authentication checks by submitting hex-encoded variants of protected administrative endpoints, gaining access to privileged management functions. Cisco disclosed the issue as an actively-exploited zero-day and it is listed in the CISA KEV catalog. This detection focuses on web/access log evidence of encoded-path requests to authentication-protected SD-WAN Manager endpoints, anomalous authenticated sessions originating from unauthenticated requests, and post-exploitation administrative activity.

Vulnerability Intelligence

KEV — Known Exploited

What is CVE-2026-76504 Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504)?

Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504) (CVE-2026-76504) maps to the Initial Access and Privilege Escalation tactics — the adversary is trying to get into your network in MITRE ATT&CK.

This page provides production-ready detection logic for Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504), covering the data sources and telemetry it touches: Web Server Logs, IIS Logs, Reverse Proxy Logs. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Initial Access Privilege Escalation
Microsoft Sentinel / Defender
kusto
let authBypassPaths = dynamic(["/dataservice", "/clusterManagement", "/j_security_check", "/admin", "/apidocs"]);
let encodedMarkers = dynamic(["%2e", "%2f", "%5c", "%25", "%2E", "%2F", "%5C"]);
W3CIISLog
| where csUriStem has_any (encodedMarkers) or csUriQuery has_any (encodedMarkers)
| where csUriStem has_any (authBypassPaths) or csUriStem has "dataservice"
| where scStatus in (200, 302, 401)
| extend DecodedPath = url_decode(csUriStem)
| where DecodedPath has_any (authBypassPaths)
| summarize RequestCount = count(), StatusCodes = make_set(scStatus), SamplePaths = make_set(csUriStem, 10) by cIP, csHost, bin(TimeGenerated, 10m)
| where RequestCount >= 1
| order by TimeGenerated desc

Flags IIS/web proxy requests to Cisco SD-WAN Manager with hex/percent-encoded path separators or dot segments targeting authentication-protected endpoints, where the decoded path resolves to a privileged route — the signature of CVE-2026-76504 encoding-based auth bypass.

critical severity medium confidence

Data Sources

Web Server Logs IIS Logs Reverse Proxy Logs

Required Tables

W3CIISLog

False Positives

  • Legitimate administrators whose browser or client library percent-encodes benign characters in SD-WAN Manager URLs
  • Vulnerability scanners and authorized penetration tests probing encoded paths
  • Monitoring or automation tooling that polls /dataservice REST endpoints with URL-encoded query parameters

Sigma rule & cross-platform mapping

The detection logic for Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504) (CVE-2026-76504) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: network_connection
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Hex-encoded path separator auth bypass probe

    Expected signal: Web/IIS access log entry with an encoded URI path (%2e/%2f) targeting /dataservice and a 200 or 302 response code.

  2. Test 2Percent-encoded j_security_check bypass attempt

    Expected signal: Access log showing encoded j_security_check / dataservice admin request path.

  3. Test 3Encoded admin endpoint access via PowerShell

    Expected signal: IIS/web log entry with encoded clusterManagement path and HTTP status response.


Response Playbook

Triage

  1. Confirm the targeted host is a Cisco Catalyst SD-WAN Manager (vManage) instance and that its web management interface is reachable from the source IP observed in the alert.
  2. URL-decode the flagged request path(s) and verify whether the decoded route resolves to an authentication-protected endpoint (e.g. /dataservice, /clusterManagement, /admin) that was served a 200/302 rather than a 401/403.
  3. Correlate the source IP against threat intel and KEV exploitation reporting; determine whether it is an internal admin jump host, a known scanner, or an unrecognized external address.
  4. Review the authentication logs for the session: determine whether a valid login preceded the privileged request or whether access was granted with no corresponding authentication event (the hallmark of the bypass).

Containment

  1. Block the offending source IP(s) at the perimeter/WAF and restrict SD-WAN Manager management access to a trusted administrative network or VPN only.
  2. Apply the Cisco fixed release per advisory cisco-sa-sdwan-webauth-xr8beuuU, or disable/firewall external access to the web management interface until patched.
  3. Invalidate all active SD-WAN Manager web sessions and rotate administrative credentials and API tokens that could have been exposed.

Evidence Collection

  1. Preserve full IIS/vManage web access logs, application logs, and authentication logs covering the request window for forensic analysis.
  2. Capture the SD-WAN Manager configuration database state and audit logs to identify any device template, policy, or admin account changes made during the suspect session.

Escalation Criteria

  • ! Escalate to incident response immediately if a privileged endpoint returned 200/302 to an unauthenticated encoded request, indicating successful bypass.
  • ! Escalate if post-exploitation activity is observed — new admin accounts, modified device templates/policies, configuration pushes to managed edge devices, or outbound connections from the SD-WAN Manager host.

Investigation Guide

Forensic Artifacts

  • > IIS/vManage web access logs showing encoded request paths with 200/302 responses to protected endpoints
  • > SD-WAN Manager application and audit logs recording privileged actions with absent or mismatched authentication context
  • > Configuration database change history (device templates, policies, admin accounts) correlated to the suspect session timeframe

Tuning Guidance

Establish a baseline of legitimate administrative source IPs and automation hosts that interact with /dataservice so those can be allow-listed or down-weighted. Tighten the response-code filter to 200/302 only (drop 401) in environments where probing noise is high. If the vManage interface is already restricted to a management VLAN/VPN, treat any match from outside that range as high-fidelity. Review the encoded-marker list against your decoder behaviour — some proxies normalize %2f before logging, in which case rely on upstream raw logs or WAF logs for detection.


Hunting Queries

Surfaces all SD-WAN Manager requests whose URL-encoded path differs from its decoded form and resolves to a protected endpoint served successfully — the core exploitation pattern for CVE-2026-76504.

Hunting — KQL
kql
W3CIISLog | where csUriStem has "dataservice" or csUriStem has "clusterManagement" | extend Decoded = url_decode(csUriStem) | where csUriStem != Decoded | where scStatus in (200,302) | project TimeGenerated, cIP, csHost, csUriStem, Decoded, scStatus | order by TimeGenerated desc
Hunting — SPL
spl
index=web (sourcetype=iis OR sourcetype=cisco:sdwan:vmanage) | eval decoded=urldecode(cs_uri_stem) | where cs_uri_stem!=decoded AND match(decoded,"(?i)(dataservice|clusterManagement|admin)") AND sc_status IN (200,302) | table _time c_ip cs_host cs_uri_stem decoded sc_status

Atomic Red Team Tests

Test 1 Hex-encoded path separator auth bypass probe
linux

Simulate CVE-2026-76504 by requesting a protected SD-WAN Manager endpoint using hex-encoded path separators to bypass authentication (lab only, against a test instance).

Command

bash
curl -sk -o /dev/null -w '%{http_code}\n' 'https://sdwan-manager.lab.local/%2e%2e/dataservice/system/device/controllers'

Cleanup

bash
echo 'No persistent artifact created; clear any test WAF blocks for the source IP if applied.'

Expected Telemetry

Web/IIS access log entry with an encoded URI path (%2e/%2f) targeting /dataservice and a 200 or 302 response code.

Expected Detection

KQL/SPL rules fire on the encoded path whose decoded form matches a protected endpoint returning 200/302.

Test 2 Percent-encoded j_security_check bypass attempt
linux

Request the authentication handler endpoint using percent-encoding to test the encoding bypass path.

Command

bash
curl -sk 'https://sdwan-manager.lab.local/%6a_security_check/../dataservice/admin/user' -H 'Accept: application/json'

Cleanup

bash
echo 'No cleanup required; remove test request logs from lab retention if desired.'

Expected Telemetry

Access log showing encoded j_security_check / dataservice admin request path.

Expected Detection

Encoded-path detection matches the request and decoded admin endpoint.

Test 3 Encoded admin endpoint access via PowerShell
windows

Windows-based simulation issuing an encoded request to a protected SD-WAN Manager admin route.

Command

powershell
powershell -Command "[Net.ServicePointManager]::ServerCertificateValidationCallback={$true}; Invoke-WebRequest -UseBasicParsing -Uri 'https://sdwan-manager.lab.local/%2e%2e%2f/clusterManagement/health/status' | Select-Object StatusCode"

Cleanup

powershell
powershell -Command "[Net.ServicePointManager]::ServerCertificateValidationCallback=$null"

Expected Telemetry

IIS/web log entry with encoded clusterManagement path and HTTP status response.

Expected Detection

Detection rules identify the encoded path resolving to clusterManagement with a success/redirect status.

Related Detections