VDB

CVE-2026-76432

CVE-2026-76432 PUBLISHED CVSS 4.9 MEDIUM

Reported by cisco · Published September 16, 2026

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to write files to an arbitrary location on the affected system.

Risk Scores

CVSS 3.1
4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.1.0, 3.1.0 p1, 3.1.0 p3
CiscoCisco ISE Passive Identity Connector3.2.0, 3.1.0, 3.3.0
CiscoCisco ISE Passive Identity Connector3.2.0, 3.1.0, 3.3.0
CiscoCisco Identity Services Engine Software3.1.0 p7, 3.3.0, 3.2.0 p3

Timeline

  • Sep 16, 2026 Coalition ESS Score
  • Sep 16, 2026 CVE Published
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 19, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›