VDB
CVE-2026-76444
CVE-2026-76444
PUBLISHED
CVSS 5.3 MEDIUM
Reported by cisco · Published September 16, 2026
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.
Risk Scores
CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.4.0, 3.4 Patch 1, 3.4 Patch 2 |
| Cisco | Cisco ISE Passive Identity Connector | 3.4.0, 3.5.0 |
| Cisco | Cisco Identity Services Engine Software | 3.4.0, 3.4 Patch 1, 3.4 Patch 2 |
| Cisco | Cisco ISE Passive Identity Connector | 3.4.0, 3.5.0, 3.4.0 |
Timeline
- Sep 16, 2026 Coalition ESS Score
- Sep 16, 2026 CVE Published
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score