Executive brief
Cisco Identity Services Engine (ISE) and ISE-PIC, which are identity and access management systems used to control network authentication and authorization, contain a path traversal vulnerability in the certificate management interface. An authenticated attacker with administrative credentials can exploit this flaw to read arbitrary files from the affected system, potentially exposing sensitive configuration data, credentials, or other confidential information stored on the device.
Technical details
This is a path traversal vulnerability (CWE-22) in the certificate import functionality of the web-based management interface. The root cause is insufficient validation of directory traversal sequences (e.g., "../") in user-supplied file paths during certificate import operations. The vulnerability requires network access and valid administrative credentials to exploit. An authenticated remote attacker can send a crafted request containing path traversal payloads to the web interface, allowing them to read arbitrary files outside the intended directory. Cisco has released software patches to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine multiple versions
- Cisco ISE Passive Identity Connector multiple versions
Timeline
- 2026-09-16: disclosed: CVE-2026-76434 published