A CVSS 10.0 authentication bypass in the Cisco Identity Services Engine REST API lets a remote, unauthenticated attacker read and modify ISE configuration and identity data with administrative privileges.
What Is It
Cisco ISE and Cisco ISE-PIC expose a REST API web service that can be tricked into accepting a spoofed, unauthenticated request. An attacker can exploit the flaw by sending a crafted HTTP request to the exposed REST API port; no credentials, no user interaction, no prior foothold. A successful exploit grants administrative access to the affected device, including the ability to read and modify ISE configuration and identity data.
Cisco's PSIRT classifies the weakness as CWE-290 (Authentication Bypass by Spoofing) and scores it CVSS 3.1 10.0 CRITICAL, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L. The scope-changed metric reflects that compromise of the API does not stay contained to the API itself.
Why It Matters
ISE is the policy and identity control plane for the network it serves; it decides who authenticates, what they can reach, and under what posture. Administrative read/write on that control plane means an attacker can inspect identity data and rewrite the access policy that everything downstream trusts. A perfect 10.0 with network attack vector, low complexity, and no privileges required is about as low-friction as remote exploitation gets.
The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation or a KEV-mandated remediation deadline in this source material. The KEV catalog is updated continuously; check it directly for current status.
What's Vulnerable
- Cisco Identity Services Engine Software: the 3.1, 3.2, 3.3, 3.4, and 3.5 trains, spanning base releases and their patch levels (3.1.0 through 3.1.0 p11, 3.2.0 through 3.2 Patch 10, 3.3.0 through 3.3 Patch 12, 3.4.0 through 3.4 Patch 6, and 3.5.0 through 3.5 Patch 3).
- Cisco ISE Passive Identity Connector (ISE-PIC): 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0.
That range spans five major trains and their enumerated patch levels. Whether it accounts for every currently supported release is not established by this data; treat the Cisco advisory as the authoritative affected-version matrix.
Patch Status
The CVE was published 2026-09-16 and remains in "Awaiting Analysis" status at NVD. Fixed-version and remediation guidance is carried in the Cisco security advisory cisco-sa-ise-multi-hrP9jQSQ; consult it directly for fixed release mapping. No required-action deadline is present in the supplied data. Given the exposure model, restricting network reachability of the ISE REST API port is the relevant interim consideration until fixed builds are applied.
Sources
- NVD, CVE-2026-76423: https://nvd.nist.gov/vuln/detail/CVE-2026-76423
- Cisco Security Advisory (cisco-sa-ise-multi-hrP9jQSQ): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog