Skip to content

CVE-2026-76423 CVE-2026-76425 CVE-2026-76424 CVE-2026-76426 CVE-2026-76427 CVE-2026-76428

Cisco ISE REST API authentication bypass allows unauthenticated administrative access (CVE-2026-76423)

Critical 10.0 Vendor: Cisco Published

Cisco ISE and ISE-PIC are affected by multiple vulnerabilities, including CVE-2026-76423, an unauthenticated REST API authentication bypass with CVSS 10. Fixes are available; apply Cisco's fixed software and restrict exposure.

What happened

Six vulnerabilities are documented in Cisco's advisory. The most severe, CVE-2026-76423, is in the REST API of Cisco ISE and Cisco ISE-PIC. The REST API can be reached over the network without authentication, because authorization checks on the exposed service are insufficient. A remote attacker who can reach the API can send a crafted HTTP request and gain administrative access, allowing them to read and modify ISE configuration and identity data. The CVSS 3.1 score is 10, with high confidentiality and integrity impact and limited availability impact.

The other vulnerabilities require a valid administrative account. CVE-2026-76424 allows an authenticated remote attacker to upload or copy files to arbitrary locations and execute commands as root through the REST API. CVE-2026-76425 and CVE-2026-76426 are SQL injection issues in APIs; the former can read database content and carry out server-side request forgery, while the latter reads the monitoring database. CVE-2026-76428 is a further SQL injection affecting the session database, and CVE-2026-76427 is an XML external entity issue in the offline profiler feed that can read arbitrary files and issue requests to internal systems.

Cisco PSIRT has stated it is not aware of public announcements or malicious use of these vulnerabilities, and they are not listed in CISA KEV. However, the highest-severity issue is remotely reachable without credentials, so there is no user interaction or prior access required for an attacker who can reach the API.

Who is affected

Affected versions are: Cisco Identity Services Engine Software 3.1.0, 3.1.0 p1, 3.1.0 p2, 3.1.0 p3, 3.1.0 p4, 3.1.0 p5, 3.2.0, and 3.2.0 p1. Cisco ISE Passive Identity Connector 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0. Not every vulnerability affects both products, so confirm the specific mapping in Cisco's advisory for your deployment.

What to do now

  1. Review the Cisco security advisory for your version and apply the fixed software Cisco has made available.
  2. There are no workarounds that address these vulnerabilities, according to Cisco, so patching is the primary mitigation.
  3. Until patching is complete, restrict access to the Cisco ISE REST API and management interfaces so they are reachable only from trusted administrative networks. If the REST API is not required, disable or firewall it.

How to detect it

Because the critical issue is reachable only through an exposed REST API port, inventory your ISE REST API and management interfaces and confirm they are not reachable from untrusted network segments.

Beyond the patch

The entry point for the worst of this is an exposed service reachable without credentials — the kind of exposure Virtual CISO Services (vCISO) is meant to catch. If administrative access is taken before patching, the resulting privilege abuse and command execution is the sort of activity Managed Detection & Response (MDR) should detect and escalate. Apply the fix first, then make Cisco ISE part of your exposure inventory and detection scope.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76423
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76423
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-76425
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76424
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76426
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76426
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-76427
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76427
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-76428
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-76428
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.