CVE-2026-76423: pre-auth administrative access in Cisco Cisco Identity Services Engine Software

Unauthenticated remote attackers can obtain full administrative control of Cisco Identity Services Engine Software under CVE-2026-76423. The flaw affects releases in the 3.x line identified as 3.1.0 (including p1–p6) and 3.2.0 (including p1–p2). The REST API endpoint does not enforce adequate authorization, so an attacker with network reach to that API port can send a specially crafted HTTP request to read and change ISE configuration and identity records with admin privileges.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.00583
CWE
CWE-290
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat this as high priority because no login is required and successful attacks grant administrative control; immediately block or restrict access to the REST API and follow any Cisco guidance when published.

What is CVE-2026-76423?

Unauthenticated remote attackers can obtain full administrative control of Cisco Identity Services Engine Software under CVE-2026-76423. The flaw affects releases in the 3.x line identified as 3.1.0 (including p1–p6) and 3.2.0 (including p1–p2). The REST API endpoint does not enforce adequate authorization, so an attacker with network reach to that API port can send a specially crafted HTTP request to read and change ISE configuration and identity records with admin privileges.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Which versions of Cisco Cisco Identity Services Engine Software are affected?

BRANCHAFFECTEDFIXED
Cisco Identity Services Engine Software 3.x3.1.0
Cisco Identity Services Engine Software 3.x3.1.0 p1
Cisco Identity Services Engine Software 3.x3.1.0 p3
Cisco Identity Services Engine Software 3.x3.1.0 p2
Cisco Identity Services Engine Software 3.x3.2.0
Cisco Identity Services Engine Software 3.x3.1.0 p4
Cisco Identity Services Engine Software 3.x3.1.0 p5
Cisco Identity Services Engine Software 3.x3.2.0 p1
Cisco Identity Services Engine Software 3.x3.1.0 p6
Cisco Identity Services Engine Software 3.x3.2.0 p2

Is CVE-2026-76423 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-76423

  1. Block or restrict access to the ISE REST API port to trusted management subnets and VPNs only.
  2. Remove direct internet exposure of ISE and enforce network-level controls (firewall, ACLs) around management interfaces.
  3. Enable and review detailed API and admin-change logging to detect suspicious requests and configuration modifications.
  4. Follow Cisco advisories and apply vendor-provided patches or mitigations as soon as they are released.

Frequently asked questions

Is CVE-2026-76423 being actively exploited?

There are no public reports of exploitation of CVE-2026-76423 as of 2026-09-30.

Which Cisco Identity Services Engine Software versions are affected by CVE-2026-76423?

Affected versions listed are 3.1.0, 3.1.0 p1, p2, p3, p4, p5, p6, 3.2.0, 3.2.0 p1, and 3.2.0 p2.

Is there a patch for CVE-2026-76423?

No patch is available for CVE-2026-76423 as of 2026-09-30.

Does CVE-2026-76423 require authentication?

No; the vulnerability can be exploited without authentication if the attacker can reach the ISE REST API port.

References