Path traversal in Cisco Identity Services Engine (ISE) - CVE-2026-76434
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary files.
The vulnerability exists due to insufficient validation of user-supplied input in the certificate import functionality of the web-based management interface when processing certificate import requests. A remote privileged user can send a crafted request to the web-based management interface to read arbitrary files.