Directory Traversal Vulnerability in Cisco Identity Services Engine
CVE-2026-76431

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76431?

A vulnerability in the file management feature of the web-based management interface of Cisco Identity Services Engine (ISE) allows an authenticated remote attacker to delete arbitrary files and directories on the affected device. This flaw arises from inadequate validation of directory traversal sequences in user-supplied file paths. By crafting a malicious request to the Cisco ISE management interface, an attacker with valid administrative credentials can potentially exploit this issue, leading to significant consequences on the device's operating system and its data integrity.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.