Insufficient Access Control in Cisco APIC Affects Sensitive File Security
CVE-2026-76488

6.5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

Badges

👾 Exploit Exists

What is CVE-2026-76488?

A vulnerability in the export policies functionality of Cisco’s Application Policy Infrastructure Controller (APIC) allows authenticated remote attackers to exploit insufficient access control to sensitive file system resources. By providing specifically crafted inputs via certain UI fields, attackers with valid administrative credentials could access critical files, including key materials that may enable them to escalate privileges to root on the affected APIC and any managed switches. Organizations utilizing Cisco APIC should take the necessary precautions to mitigate potential breaches.

Affected Version(s)

Cisco Application Policy Infrastructure Controller (APIC) 5.2(1g)

Cisco Application Policy Infrastructure Controller (APIC) 5.2(2e)

Cisco Application Policy Infrastructure Controller (APIC) 5.2(2f)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.