Missing Authentication for Critical Function in Cisco Identity Services Engine (ISE) - CVE-2026-76439
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to manipulate endpoint posture status.
The vulnerability exists due to insufficient authentication in the endpoint posture status reporting functionality of the guest portal web application when sending crafted requests to an internal interface exposed through the guest portal. A remote attacker can submit forged posture status events to manipulate endpoint posture status.