Junglewise Threat Intelligence

CVE-2026-76423: Cisco ISE REST API authentication bypass

CVE-2026-76423 · Severity: critical · CVSS 10 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is an identity and access management platform that controls network access and device authentication for enterprises. A critical vulnerability in its REST API allows unauthenticated remote attackers to gain administrative access without credentials, enabling them to read and modify all ISE configuration and identity data. This could lead to network access policy manipulation, credential theft, and complete compromise of access controls.

Technical details

CVE-2026-76423 is an authentication bypass vulnerability in the Cisco ISE REST API resulting from insufficient authorization checks on the exposed web service. An attacker can send a crafted HTTP request to the REST API port without providing valid credentials to achieve administrative access. The vulnerability has a CVSS score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicating it requires no authentication, no user interaction, and affects multiple systems. A successful exploit grants full read and write access to ISE configuration and identity data. Cisco has released software patches; no workarounds are available.

Affected products

  • Cisco Identity Services Engine <UNKNOWN>
  • Cisco Identity Services Engine Passive Identity Connector <UNKNOWN>

Timeline

  • 2026-09-16: disclosed: CVE-2026-76423 published

References

Related threats