SB20260917232 - Multiple authentication bypass vulnerabilities in Cisco Identity Services Engine



SB20260917232 - Multiple authentication bypass vulnerabilities in Cisco Identity Services Engine

Published: September 17, 2026

Security Bulletin ID SB20260917232
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Missing Authentication for Critical Function (CVE-ID: CVE-2026-76439)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to manipulate endpoint posture status.

The vulnerability exists due to insufficient authentication in the endpoint posture status reporting functionality of the guest portal web application when sending crafted requests to an internal interface exposed through the guest portal. A remote attacker can submit forged posture status events to manipulate endpoint posture status.


2) Missing Authentication for Critical Function (CVE-ID: CVE-2026-76444)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain sensitive configuration information.

The vulnerability exists due to missing authentication in the Policy Runtime Repository Table (PRRT) service when handling crafted requests. A remote attacker can send a crafted request to obtain sensitive configuration information.


3) XML External Entity injection (CVE-ID: CVE-2026-76446)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to read specific files on the underlying operating system.

The vulnerability exists due to improper restriction of XML external entity references in an API when processing crafted requests. A remote privileged user can send a crafted request to read specific files on the underlying operating system.

Accessible files are limited to those that the underlying process has permission to access.


4) Missing Authentication for Critical Function (CVE-ID: CVE-2026-76447)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the OCSP responder to reload certificate and key material.

The vulnerability exists due to missing authentication in a function of the Online Certificate Status Protocol (OCSP) responder when handling crafted requests. A remote attacker can send a crafted request to cause the OCSP responder to reload certificate and key material on demand.


Remediation

Install update from vendor's website.