Missing Authentication for Critical Function in Cisco Identity Services Engine (ISE) - CVE-2026-76439

 

Missing Authentication for Critical Function in Cisco Identity Services Engine (ISE) - CVE-2026-76439

Published: September 17, 2026


Vulnerability identifier: #VU150679
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76439
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate endpoint posture status.

The vulnerability exists due to insufficient authentication in the endpoint posture status reporting functionality of the guest portal web application when sending crafted requests to an internal interface exposed through the guest portal. A remote attacker can submit forged posture status events to manipulate endpoint posture status.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2026-76439

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

External References

Related Security Bulletins