Junglewise Threat Intelligence

CVE-2026-76424: Cisco ISE arbitrary file upload and execution

CVE-2026-76424 · Severity: high · CVSS 7.2 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is an authentication and access control platform used to manage network identity and access policies. A flaw in its REST API allows authenticated administrators with valid credentials to upload files to arbitrary locations on the device and execute arbitrary commands with root privileges, potentially compromising the entire network infrastructure managed by ISE.

Technical details

CVE-2026-76424 is a path traversal / arbitrary file upload vulnerability in the Cisco ISE REST API caused by insufficient validation of file operation parameters. An authenticated attacker with valid administrative credentials can upload a file with a crafted path to bypass directory restrictions and place malicious files at arbitrary locations on the affected device. A successful exploit allows execution of arbitrary commands with root privileges. The vulnerability requires network access to the REST API port and valid administrative credentials; no user interaction is needed. Cisco has released software updates to address this issue, with no known workarounds available.

Affected products

  • Cisco Identity Services Engine See Cisco advisory for affected versions

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: advisory: Cisco Security Advisory cisco-sa-ise-multi-hrP9jQSQ published

References

Related threats