Remote File Reading Vulnerability in Cisco ISE and Cisco ISE-PIC
CVE-2026-76434

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76434?

A vulnerability exists in the certificate import function of the web-based management interface for Cisco Identity Services Engine (ISE) and Cisco ISE-PIC. An attacker with valid administrative credentials could craft a specialized request that exploits insufficient validation of user-supplied input. Successfully exploiting this vulnerability could allow the attacker to read arbitrary files from the affected device, potentially exposing sensitive information. To mitigate the risk, it is essential for organizations using these products to follow recommended security practices and stay updated with the latest patches.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.