Directory Traversal Vulnerability in Cisco ISE and Cisco ISE-PIC
CVE-2026-76433
5.3MEDIUM
What is CVE-2026-76433?
A vulnerability exists in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC, allowing unauthenticated remote attackers to exploit insufficient validation of directory traversal character sequences within user-supplied paths. By sending crafted requests to the provisioning download service, attackers could access protected files without proper authentication, potentially exposing sensitive information stored on affected devices. This flaw highlights the importance of validating input in network services to prevent unauthorized access.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3