CVE-2026-76423 CVE-2026-76425 CVE-2026-76424 CVE-2026-76426 CVE-2026-76427 CVE-2026-76428
Cisco ISE REST API authentication bypass allows unauthenticated administrative access (CVE-2026-76423)
Cisco ISE and ISE-PIC are affected by multiple vulnerabilities, including CVE-2026-76423, an unauthenticated REST API authentication bypass with CVSS 10. Fixes are available; apply Cisco's fixed software and restrict exposure.
What happened
Six vulnerabilities are documented in Cisco's advisory. The most severe, CVE-2026-76423, is in the REST API of Cisco ISE and Cisco ISE-PIC. The REST API can be reached over the network without authentication, because authorization checks on the exposed service are insufficient. A remote attacker who can reach the API can send a crafted HTTP request and gain administrative access, allowing them to read and modify ISE configuration and identity data. The CVSS 3.1 score is 10, with high confidentiality and integrity impact and limited availability impact.
The other vulnerabilities require a valid administrative account. CVE-2026-76424 allows an authenticated remote attacker to upload or copy files to arbitrary locations and execute commands as root through the REST API. CVE-2026-76425 and CVE-2026-76426 are SQL injection issues in APIs; the former can read database content and carry out server-side request forgery, while the latter reads the monitoring database. CVE-2026-76428 is a further SQL injection affecting the session database, and CVE-2026-76427 is an XML external entity issue in the offline profiler feed that can read arbitrary files and issue requests to internal systems.
Cisco PSIRT has stated it is not aware of public announcements or malicious use of these vulnerabilities, and they are not listed in CISA KEV. However, the highest-severity issue is remotely reachable without credentials, so there is no user interaction or prior access required for an attacker who can reach the API.
Who is affected
Affected versions are: Cisco Identity Services Engine Software 3.1.0, 3.1.0 p1, 3.1.0 p2, 3.1.0 p3, 3.1.0 p4, 3.1.0 p5, 3.2.0, and 3.2.0 p1. Cisco ISE Passive Identity Connector 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0. Not every vulnerability affects both products, so confirm the specific mapping in Cisco's advisory for your deployment.
What to do now
- Review the Cisco security advisory for your version and apply the fixed software Cisco has made available.
- There are no workarounds that address these vulnerabilities, according to Cisco, so patching is the primary mitigation.
- Until patching is complete, restrict access to the Cisco ISE REST API and management interfaces so they are reachable only from trusted administrative networks. If the REST API is not required, disable or firewall it.
How to detect it
Because the critical issue is reachable only through an exposed REST API port, inventory your ISE REST API and management interfaces and confirm they are not reachable from untrusted network segments.
Beyond the patch
The entry point for the worst of this is an exposed service reachable without credentials — the kind of exposure Virtual CISO Services (vCISO) is meant to catch. If administrative access is taken before patching, the resulting privilege abuse and command execution is the sort of activity Managed Detection & Response (MDR) should detect and escalate. Apply the fix first, then make Cisco ISE part of your exposure inventory and detection scope.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-76423 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76423 Cisco ISE Passive Identity Connector | 3.2.0 3.1.0 3.3.0 3.4.0 3.5.0 | No fixed version listed yet |
| CVE-2026-76425 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76424 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76426 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76426 Cisco ISE Passive Identity Connector | 3.2.0 3.1.0 3.3.0 3.4.0 3.5.0 | No fixed version listed yet |
| CVE-2026-76427 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76427 Cisco ISE Passive Identity Connector | 3.2.0 3.1.0 3.3.0 3.4.0 3.5.0 | No fixed version listed yet |
| CVE-2026-76428 Cisco Identity Services Engine Software | 3.1.0 3.1.0 p1 3.1.0 p3 3.1.0 p2 3.2.0 3.1.0 p4 3.1.0 p5 3.2.0 p1 | No fixed version listed yet |
| CVE-2026-76428 Cisco ISE Passive Identity Connector | 3.2.0 3.1.0 3.3.0 3.4.0 3.5.0 | No fixed version listed yet |