CVE-2026-76423
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- CWE
- CWE-290
- Published
- 2026-09-16
- Last modified
- 2026-09-17
Affected products
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
- Cisco Cisco Identity Services Engine Software
Weakness type
Related vulnerabilities
- CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2026-33654 — Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
- CVE-2026-31889 — Shopware has a potential take over of app credentials
- CVE-2026-33661 — WeChat Pay callback signature verification bypassed when Host header is localhost
- CVE-2026-6213 — Remote Spark SparkView RCE
- CVE-2026-54782 — CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
- CVE-2026-14450 — Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication