Directory Traversal Vulnerability in Cisco ISE and Cisco ISE-PIC
CVE-2026-76433

5.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76433?

A vulnerability exists in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC, allowing unauthenticated remote attackers to exploit insufficient validation of directory traversal character sequences within user-supplied paths. By sending crafted requests to the provisioning download service, attackers could access protected files without proper authentication, potentially exposing sensitive information stored on affected devices. This flaw highlights the importance of validating input in network services to prevent unauthorized access.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.