Path traversal in Cisco Identity Services Engine (ISE) - CVE-2026-76433
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to access protected files.
The vulnerability exists due to insufficient validation of directory traversal character sequences in the client provisioning download feature when processing provisioning resource requests. A remote attacker can send a crafted request to the provisioning download service to access protected files.