CVE-2026-76423
Cisco ISE API Authentication Bypass Vulnerability
Description
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.
In plain language
AI Act nowThis is a critical flaw in Cisco Identity Services Engine software and Cisco ISE Passive Identity Connector that can let an outsider take administrator control; act urgently, but Cisco has not yet published a fix.
Unauthenticated remote administrative access is possible through insufficient authorization checks in the exposed REST API web service, allowing crafted HTTP requests to read and alter identity and configuration data.
What to do now
- Check whether you run Cisco Identity Services Engine software or Cisco ISE Passive Identity Connector and whether its management API can be reached from outside your management network.
- Restrict access to the API immediately: allow only trusted administrator networks and block all unnecessary internet access to management ports.
- There is no Cisco fixed version available yet; ask Cisco or your support provider for the remediation release and apply it as soon as it is published.
- Review administrator accounts, API activity, and recent configuration changes for anything unexpected.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76423 and every CVE in our database. Create a free account — no credit card required.
Create Free Account