Missing Authorization in Cisco Identity Services Engine (ISE) - CVE-2026-76423

 

Missing Authorization in Cisco Identity Services Engine (ISE) - CVE-2026-76423

Published: September 17, 2026


Vulnerability identifier: #VU150698
CSH Severity: Critical
CVSS v4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-76423
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain administrative access and read and modify configuration and identity data.

The vulnerability exists due to insufficient authorization checks in the REST API web service when handling crafted HTTP requests to the exposed REST API port. A remote attacker can send a crafted HTTP request to gain administrative access and read and modify configuration and identity data.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2026-76423

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

External References

Related Security Bulletins