Executive brief
Cisco ISE and ISE-PIC are identity management systems used to control network access and device authentication. A missing authentication check in an internal service allows remote attackers to retrieve sensitive configuration data without credentials, potentially exposing policy rules, user information, and other critical settings.
Technical details
This vulnerability (CVE-2026-76444) is an authentication bypass in the Policy Runtime Repository Table (PRRT) service, classified as CWE-306 (Missing Authentication Check). The root cause is missing authentication controls on the PRRT service, which is normally an internal component but is accessible over the network. An unauthenticated, remote attacker can send a crafted request to an affected Cisco ISE or ISE-PIC device and retrieve sensitive configuration information. No user interaction or authentication is required. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine
- Cisco Identity Services Engine Passive Identity Connector
Timeline
- 2026-09-16: disclosed: CVE-2026-76444 publicly disclosed