Attackers are using a URI-encoding bypass to enter Cisco Catalyst SD-WAN Manager as administrators.
Encoding one character prevents the API authentication rule from matching the endpoint path.
Cisco Catalyst SD-WAN Manager, the management and orchestration component for Cisco SD-WAN deployments.
Unauthenticated API access with administrator privileges
This is an actively exploited failure of the administrative boundary around an enterprise SD-WAN control plane.
Detail and 2 sources
Any unauthenticated caller who can reach the Manager API can attempt the bypass.
The crafted URI misses the authentication rule and receives administrator-level API access.
Cisco confirms active exploitation and has published fixed releases.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- No
- Reaches end-of-life hardware
- No
Cisco does not publish the underlying patch diff; these conclusions rely on its current remediation and lifecycle documentation.