CVE-2026-76432

Cisco Identity Services Engine Arbitrary File Write Vulnerability

Severity
Medium 4.9
CVSS 3.1
Exploited
Not listed
EPSS
0.009
57.6th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 16, 2026
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to write files to an arbitrary location on the affected system.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Cisco Cisco ISE Passive Identity Connector Identity / IAM / MFA cna-assigner
Cisco Cisco Identity Services Engine (ISE) Identity / IAM / MFA cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco Identity Services Engine Software
  • Cisco · Cisco ISE Passive Identity Connector

Something wrong here?