Junglewise Threat Intelligence

CVE-2026-76431: Cisco ISE arbitrary file deletion in web management interface

CVE-2026-76431 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is an authentication and access control system used to manage network security policies. A vulnerability in its web-based file management function allows authenticated administrators to delete arbitrary files from the system, potentially disrupting critical security infrastructure and operations. An attacker with valid admin credentials could systematically destroy system files, causing denial of service or compromising the integrity of the security platform.

Technical details

This is a path traversal vulnerability (CWE-22) in the file management function of the Cisco ISE web-based management interface. The vulnerability exists due to improper validation of directory traversal character sequences (e.g., "../") in user-supplied file paths before deletion is performed. An authenticated remote attacker with administrative credentials can exploit this by sending a crafted request containing directory traversal sequences to bypass path restrictions and delete arbitrary files and directories on the underlying operating system. The vulnerability is network-reachable, requires valid administrative authentication, and no user interaction is needed. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Identity Services Engine (ISE)
  • Cisco ISE Passive Identity Connector (ISE-PIC)

Timeline

  • 2026-09-16: disclosed: CVE-2026-76431 published

References

Related threats