Path traversal in Cisco Identity Services Engine (ISE) - CVE-2026-76431
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to delete arbitrary files and directories.
The vulnerability exists due to improper validation of directory traversal character sequences in the file management function of the web-based management interface when validating user-supplied file paths. A remote privileged user can send a crafted request to the web-based management interface to delete arbitrary files and directories.
The files and directories may be deleted from the underlying operating system.