# CVE-2026-76423

## Summary

- **CVE ID:** CVE-2026-76423
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
- **CWE:** CWE-290
- **Published:** Sep 16, 2026
- **Last Modified:** Sep 17, 2026

## Description

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device.

This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.

## Affected Products

- Cisco — Cisco Identity Services Engine Software (3.1.0)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p3)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p2)
- Cisco — Cisco Identity Services Engine Software (3.2.0)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p4)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p5)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p6)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p2)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p7)
- Cisco — Cisco Identity Services Engine Software (3.3.0)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p3)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p4)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p8)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p5)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p6)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p9)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.4.0)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p7)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 4)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p10)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 5)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 6)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 7)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.5.0)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 4)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 8)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 8)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 9)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 9)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 5)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 10)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 11)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 6)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 10)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p72)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p11)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 12)
- Cisco — Cisco ISE Passive Identity Connector (3.2.0)
- Cisco — Cisco ISE Passive Identity Connector (3.1.0)
- Cisco — Cisco ISE Passive Identity Connector (3.3.0)
- Cisco — Cisco ISE Passive Identity Connector (3.4.0)
- Cisco — Cisco ISE Passive Identity Connector (3.5.0)

## References

- [CNA](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.55%
- **EPSS Percentile:** 44.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._