Unauthenticated Endpoint Posture Manipulation in Cisco ISE Guest Portal
CVE-2026-76439

5.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76439?

A vulnerability exists within the endpoint posture status reporting of the guest portal web application in Cisco Identity Services Engine (ISE). This flaw arises from inadequate authentication mechanisms on an internal interface accessible through the guest portal. It enables an unauthenticated, remote attacker to forge posture status events, effectively allowing manipulation of the endpoint posture assessment. Attackers can exploit this by sending crafted requests to the vulnerable application, which could compromise the integrity of the posture information and potentially lead to unauthorized access or control over the device.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.