Insufficient Access Control in Cisco APIC Affects Sensitive File Security
CVE-2026-76488
What is CVE-2026-76488?
A vulnerability in the export policies functionality of Cisco’s Application Policy Infrastructure Controller (APIC) allows authenticated remote attackers to exploit insufficient access control to sensitive file system resources. By providing specifically crafted inputs via certain UI fields, attackers with valid administrative credentials could access critical files, including key materials that may enable them to escalate privileges to root on the affected APIC and any managed switches. Organizations utilizing Cisco APIC should take the necessary precautions to mitigate potential breaches.
Affected Version(s)
Cisco Application Policy Infrastructure Controller (APIC) 5.2(1g)
Cisco Application Policy Infrastructure Controller (APIC) 5.2(2e)
Cisco Application Policy Infrastructure Controller (APIC) 5.2(2f)