Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-76504-Proof-of-concept — EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177) | Kitploit
Tools/GitHubGitHub/shadowforge-cyber/cve-2026-76504-proof-of-concept
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationRed TeamingAPI Security
GitHub
shadowforge-cyber/cve-2026-76504-proof-of-concept

CVE-2026-76504-Proof-of-concept

EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)

View Repository
24 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Cisco Catalyst SD-WAN Manager — CVE-2026-76504

Unauthenticated authentication bypass caused by improper handling of URL encoding (CWE-177) in the API session management layer.
A crafted request reaches a privileged endpoint and is treated as an authenticated admin session.

Overview

The vulnerability allows a remote unauthenticated attacker to bypass intended access controls on the Catalyst SD-WAN Manager API. Once the bypass succeeds, the attacker operates with full administrative privileges and can read configuration, modify system state, or issue management commands.

Affected Versions

Tested and confirmed working on:

  • 20.9.x prior to 20.9.10.1
  • 20.12.x prior to 20.12.8.2
  • 20.15.x prior to 20.15.6.1
  • 20.18.x prior to 20.18.4.1
  • 26.1.x prior to 26.1.2.1
  • 26.2 prior to 26.2.1

Root Cause

URI decoding is performed inconsistently. Certain hex-encoded sequences are accepted by the request router but are not normalized before the authentication decision. As a result, the session validation logic is skipped for the targeted API path.

Usage

python3 exploit.py --target https://manager.example.com --cmd "show running-config"
# verification only
python3 exploit.py --target https://manager.example.com --check

# arbitrary admin action
python3 exploit.py --target https://manager.example.com --cmd "request nms all"

Supported options:
--target / -t
--cmd / -c
--check
--proxy
-v

image

Exploit

Contact us for private access: [email protected]

Capabilities

  • Crafts the encoding bypass request
  • Establishes admin-level API context without credentials
  • Executes the supplied management command under the elevated session

Practical value
Useful for controlled validation of the vulnerability, detection engineering, and confirming that the applied patch actually blocks the encoding path.


Credits

Report & PoC: ShadowForge Cyber

Download Tool