Executive brief
Cisco Identity Services Engine (ISE) is used to manage network access and authentication. A vulnerability in the client provisioning feature allows unauthenticated attackers to access sensitive files on the system through directory traversal attacks, potentially exposing confidential information such as configuration files, credentials, or other protected data without requiring login.
Technical details
CVE-2026-76433 is a path traversal vulnerability (CWE-22) in the client provisioning download feature of Cisco ISE and ISE-PIC. The vulnerability exists due to insufficient validation of directory traversal sequences (e.g., "../") in user-supplied file paths when processing provisioning resource requests. An unauthenticated remote attacker can exploit this by sending a crafted request to the provisioning download service with directory traversal characters to access files outside the intended directory. A successful exploit allows unauthorized access to protected files without authentication. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine Multiple versions affected (see vendor advisory)
- Cisco Identity Services Engine Passive Identity Connector Multiple versions affected (see vendor advisory)
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published