REST API Vulnerability in Cisco ISE Products
CVE-2026-76423

10CRITICAL

Key Information:

Badges

๐Ÿ“ˆ Score: 132๐Ÿ‘พ Exploit Exists

What is CVE-2026-76423?

CVE-2026-76423 is a critical vulnerability discovered in the REST API of Cisco Identity Services Engine (ISE) products, which are instrumental in managing identity and access control within enterprise networks. This security flaw arises from inadequate authorization checks, allowing unauthenticated remote attackers to interact with the affected API. By exploiting this vulnerability, attackers can send malicious HTTP requests to the API endpoint, gaining unauthorized administrative access to the device. This level of access could enable them to read and modify sensitive configuration and identity data, which is vital for maintaining network security and operational efficiency. With the potential for significant disruption, organizations relying on Cisco ISE for network access control must take this threat seriously.

Potential impact of CVE-2026-76423

  1. Unauthorized Access and Control: The vulnerability allows attackers to gain administrative privileges without authentication. This could lead to unauthorized control over network policies and user identities, potentially compromising the entire identity management system.

  2. Data Manipulation and Breach: Attackers could read and modify critical configuration data and user identity information, posing a risk of data integrity issues and leading to information theft or alteration that could affect organizational security.

  3. Increased Attack Surface: With the REST API exposed without proper security measures, the vulnerability broadens the attack surface for potential exploitation. This can facilitate further malicious actions within the network, including lateral movement or additional malware deployment.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.