Cisco ISE REST API Flaw Allows Unauthenticated Admin Access, CVSS Score 10.0
Cisco disclosed a critical authentication bypass vulnerability, CVE-2026-76423, in its Identity Services Engine (ISE) REST API on September 16, 2026, assigning it a maximum CVSS v3 base score of 10.0. The flaw stems from insufficient authorization checks in the REST API, allowing a remote attacker with network access to gain full administrative control without any credentials. Affected versions span ISE releases 3.1 through 3.5, as well as the ISE Passive Identity Connector, with patches now available for each branch. Because ISE functions as a central network access control plane, a successful exploit could allow attackers to alter identity policies, manipulate device integrations, and pivot deeper into corporate infrastructure. Cisco urges administrators to apply the respective patches immediately, as the product has a broad deployment footprint with over 880,000 assets matching its fingerprint on ZoomEye.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in