Cyber & AI intelligence
Wasteland.
Briefs indexed2686
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76423 2026-09-16

Cisco ISE REST API Flaw (CVE-2026-76423) Hands Unauthenticated Attackers Full Admin Control

"A CVSS 10.0 authentication bypass in the Cisco Identity Services Engine REST API lets a remote, unauthenticated attacker read and modify ISE configuration and identity data with administrative privileges."

A CVSS 10.0 authentication bypass in the Cisco Identity Services Engine REST API lets a remote, unauthenticated attacker read and modify ISE configuration and identity data with administrative privileges.

What Is It

Cisco ISE and Cisco ISE-PIC expose a REST API web service that can be tricked into accepting a spoofed, unauthenticated request. An attacker can exploit the flaw by sending a crafted HTTP request to the exposed REST API port; no credentials, no user interaction, no prior foothold. A successful exploit grants administrative access to the affected device, including the ability to read and modify ISE configuration and identity data.

Cisco's PSIRT classifies the weakness as CWE-290 (Authentication Bypass by Spoofing) and scores it CVSS 3.1 10.0 CRITICAL, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L. The scope-changed metric reflects that compromise of the API does not stay contained to the API itself.

Why It Matters

ISE is the policy and identity control plane for the network it serves; it decides who authenticates, what they can reach, and under what posture. Administrative read/write on that control plane means an attacker can inspect identity data and rewrite the access policy that everything downstream trusts. A perfect 10.0 with network attack vector, low complexity, and no privileges required is about as low-friction as remote exploitation gets.

The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation or a KEV-mandated remediation deadline in this source material. The KEV catalog is updated continuously; check it directly for current status.

What's Vulnerable

That range spans five major trains and their enumerated patch levels. Whether it accounts for every currently supported release is not established by this data; treat the Cisco advisory as the authoritative affected-version matrix.

Patch Status

The CVE was published 2026-09-16 and remains in "Awaiting Analysis" status at NVD. Fixed-version and remediation guidance is carried in the Cisco security advisory cisco-sa-ise-multi-hrP9jQSQ; consult it directly for fixed release mapping. No required-action deadline is present in the supplied data. Given the exposure model, restricting network reachability of the ISE REST API port is the relevant interim consideration until fixed builds are applied.

Sources