Path traversal in Cisco Identity Services Engine (ISE) - CVE-2026-76431

 

Path traversal in Cisco Identity Services Engine (ISE) - CVE-2026-76431

Published: September 17, 2026


Vulnerability identifier: #VU150684
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76431
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary files and directories.

The vulnerability exists due to improper validation of directory traversal character sequences in the file management function of the web-based management interface when validating user-supplied file paths. A remote privileged user can send a crafted request to the web-based management interface to delete arbitrary files and directories.

The files and directories may be deleted from the underlying operating system.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2026-76431

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

External References

Related Security Bulletins