Directory Traversal Vulnerability in Cisco ISE Management Interface
CVE-2026-76432

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76432?

A vulnerability exists within the web-based management interface of Cisco ISE and Cisco ISE-PIC due to improper validation of directory traversal sequences in user-supplied file paths during uploads. An authenticated remote attacker with administrative privileges can exploit this flaw to upload a crafted file, potentially leading to arbitrary file writing on the device. This issue highlights the importance of secure file handling and validation mechanisms in software design to prevent unauthorized file access and modifications.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.