Missing Authorization in Cisco Identity Services Engine (ISE) - CVE-2026-76423
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain administrative access and read and modify configuration and identity data.
The vulnerability exists due to insufficient authorization checks in the REST API web service when handling crafted HTTP requests to the exposed REST API port. A remote attacker can send a crafted HTTP request to gain administrative access and read and modify configuration and identity data.