Detect Cisco Catalyst SD-WAN Manager Authentication Bypass via Hex Encoding (CVE-2026-76504) in IBM QRadar
Detects exploitation attempts against CVE-2026-76504, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The flaw (CWE-177, improper handling of hex/percent-encoded characters in URL request paths) allows a remote, unauthenticated attacker to bypass web authentication checks by submitting hex-encoded variants of protected administrative endpoints, gaining access to privileged management functions. Cisco disclosed the issue as an actively-exploited zero-day and it is listed in the CISA KEV catalog. This detection focuses on web/access log evidence of encoded-path requests to authentication-protected SD-WAN Manager endpoints, anomalous authenticated sessions originating from unauthenticated requests, and post-exploitation administrative activity.
MITRE ATT&CK
QRadar Detection Query
SELECT sourceip, destinationip, "URL", "httpResponseCode", COUNT(*) AS request_count FROM events WHERE LOGSOURCETYPENAME(devicetype) ILIKE '%web%' AND ("URL" IMATCHES '.*(%2e|%2f|%5c|%25).*') AND ("URL" IMATCHES '.*(dataservice|clusterManagement|j_security_check|/admin|apidocs).*') AND "httpResponseCode" IN ('200','302','401') GROUP BY sourceip, destinationip, "URL", "httpResponseCode" LAST 24 HOURS AQL search for encoded-path requests to Cisco SD-WAN Manager protected endpoints indicating CVE-2026-76504 auth bypass.
Data Sources
Required Tables
False Positives & Tuning
- Legitimate encoded admin requests
- Authorized security scanning
- REST automation with encoded query parameters
Other platforms for CVE-2026-76504
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Hex-encoded path separator auth bypass probe
Expected signal: Web/IIS access log entry with an encoded URI path (%2e/%2f) targeting /dataservice and a 200 or 302 response code.
- Test 2Percent-encoded j_security_check bypass attempt
Expected signal: Access log showing encoded j_security_check / dataservice admin request path.
- Test 3Encoded admin endpoint access via PowerShell
Expected signal: IIS/web log entry with encoded clusterManagement path and HTTP status response.
References (6)
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- https://nvd.nist.gov/vuln/detail/CVE-2026-76504
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
- https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
Response Playbook
Triage
- Confirm the targeted host is a Cisco Catalyst SD-WAN Manager (vManage) instance and that its web management interface is reachable from the source IP observed in the alert.
- URL-decode the flagged request path(s) and verify whether the decoded route resolves to an authentication-protected endpoint (e.g. /dataservice, /clusterManagement, /admin) that was served a 200/302 rather than a 401/403.
- Correlate the source IP against threat intel and KEV exploitation reporting; determine whether it is an internal admin jump host, a known scanner, or an unrecognized external address.
- Review the authentication logs for the session: determine whether a valid login preceded the privileged request or whether access was granted with no corresponding authentication event (the hallmark of the bypass).
Containment
- Block the offending source IP(s) at the perimeter/WAF and restrict SD-WAN Manager management access to a trusted administrative network or VPN only.
- Apply the Cisco fixed release per advisory cisco-sa-sdwan-webauth-xr8beuuU, or disable/firewall external access to the web management interface until patched.
- Invalidate all active SD-WAN Manager web sessions and rotate administrative credentials and API tokens that could have been exposed.
Evidence Collection
- Preserve full IIS/vManage web access logs, application logs, and authentication logs covering the request window for forensic analysis.
- Capture the SD-WAN Manager configuration database state and audit logs to identify any device template, policy, or admin account changes made during the suspect session.
Escalation Criteria
- !Escalate to incident response immediately if a privileged endpoint returned 200/302 to an unauthenticated encoded request, indicating successful bypass.
- !Escalate if post-exploitation activity is observed — new admin accounts, modified device templates/policies, configuration pushes to managed edge devices, or outbound connections from the SD-WAN Manager host.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
IIS/vManage web access logs showing encoded request paths with 200/302 responses to protected endpoints - >
SD-WAN Manager application and audit logs recording privileged actions with absent or mismatched authentication context - >
Configuration database change history (device templates, policies, admin accounts) correlated to the suspect session timeframe
Tuning Guidance
Establish a baseline of legitimate administrative source IPs and automation hosts that interact with /dataservice so those can be allow-listed or down-weighted. Tighten the response-code filter to 200/302 only (drop 401) in environments where probing noise is high. If the vManage interface is already restricted to a management VLAN/VPN, treat any match from outside that range as high-fidelity. Review the encoded-marker list against your decoder behaviour — some proxies normalize %2f before logging, in which case rely on upstream raw logs or WAF logs for detection.
Hunting Queries
Surfaces all SD-WAN Manager requests whose URL-encoded path differs from its decoded form and resolves to a protected endpoint served successfully — the core exploitation pattern for CVE-2026-76504.
W3CIISLog | where csUriStem has "dataservice" or csUriStem has "clusterManagement" | extend Decoded = url_decode(csUriStem) | where csUriStem != Decoded | where scStatus in (200,302) | project TimeGenerated, cIP, csHost, csUriStem, Decoded, scStatus | order by TimeGenerated desc index=web (sourcetype=iis OR sourcetype=cisco:sdwan:vmanage) | eval decoded=urldecode(cs_uri_stem) | where cs_uri_stem!=decoded AND match(decoded,"(?i)(dataservice|clusterManagement|admin)") AND sc_status IN (200,302) | table _time c_ip cs_host cs_uri_stem decoded sc_status Atomic Red Team Tests
Simulate CVE-2026-76504 by requesting a protected SD-WAN Manager endpoint using hex-encoded path separators to bypass authentication (lab only, against a test instance).
Command
curl -sk -o /dev/null -w '%{http_code}\n' 'https://sdwan-manager.lab.local/%2e%2e/dataservice/system/device/controllers' Cleanup
echo 'No persistent artifact created; clear any test WAF blocks for the source IP if applied.' Expected Telemetry
Web/IIS access log entry with an encoded URI path (%2e/%2f) targeting /dataservice and a 200 or 302 response code.
Expected Detection
KQL/SPL rules fire on the encoded path whose decoded form matches a protected endpoint returning 200/302.
Request the authentication handler endpoint using percent-encoding to test the encoding bypass path.
Command
curl -sk 'https://sdwan-manager.lab.local/%6a_security_check/../dataservice/admin/user' -H 'Accept: application/json' Cleanup
echo 'No cleanup required; remove test request logs from lab retention if desired.' Expected Telemetry
Access log showing encoded j_security_check / dataservice admin request path.
Expected Detection
Encoded-path detection matches the request and decoded admin endpoint.
Windows-based simulation issuing an encoded request to a protected SD-WAN Manager admin route.
Command
powershell -Command "[Net.ServicePointManager]::ServerCertificateValidationCallback={$true}; Invoke-WebRequest -UseBasicParsing -Uri 'https://sdwan-manager.lab.local/%2e%2e%2f/clusterManagement/health/status' | Select-Object StatusCode" Cleanup
powershell -Command "[Net.ServicePointManager]::ServerCertificateValidationCallback=$null" Expected Telemetry
IIS/web log entry with encoded clusterManagement path and HTTP status response.
Expected Detection
Detection rules identify the encoded path resolving to clusterManagement with a success/redirect status.