Junglewise Threat Intelligence

CVE-2026-76432: Cisco ISE path traversal in file upload

CVE-2026-76432 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is a network access control platform used to enforce security policies on corporate networks. A vulnerability in the web-based management interface could allow an authenticated administrator to write arbitrary files to the system by uploading crafted files, potentially compromising system integrity and enabling further attacks.

Technical details

CVE-2026-76432 is a path traversal vulnerability (CWE-22) in the file upload functionality of Cisco ISE and ISE-PIC's web-based management interface. The vulnerability exists because the software fails to properly validate directory traversal sequences (e.g., "../") in user-supplied file paths during the upload process. An authenticated remote attacker with administrative-level privileges can exploit this by uploading a crafted file with path traversal characters to write files to arbitrary locations on the affected device. A successful exploit allows arbitrary file write, potentially leading to system compromise. Cisco has released software updates to address this vulnerability.

Affected products

  • Cisco Identity Services Engine Multiple versions affected (see vendor advisory)
  • Cisco Identity Services Engine Passive Identity Connector Multiple versions affected (see vendor advisory)

Timeline

  • 2026-09-16: disclosed: CVE-2026-76432 published by Cisco

References

Related threats