Junglewise Threat Intelligence

CVE-2026-76439: Cisco ISE authentication bypass in guest portal endpoint posture

CVE-2026-76439 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is a network access control platform that enforces security policies on connected devices. An unauthenticated attacker can send crafted requests to the guest portal's endpoint posture reporting interface to forge or manipulate device posture status events, potentially allowing unauthorized devices to bypass access controls or receive elevated privileges without proper validation.

Technical details

CVE-2026-76439 is an authentication bypass vulnerability in the endpoint posture status reporting functionality exposed through the Cisco ISE guest portal web application. The vulnerability stems from insufficient authentication controls on an internal interface, allowing an unauthenticated, remote attacker to submit forged posture status events. The attack vector is network-based with no authentication or user interaction required (CVSS vector: AV:N/AC:L/PR:N/UI:N). A successful exploit allows manipulation of endpoint posture status on the affected system, which could lead to unauthorized access or policy bypass. Cisco has released software patches to address this issue; no workarounds are available.

Affected products

  • Cisco Identity Services Engine

Timeline

  • 2026-09-16: disclosed

References

Related threats