CVE-2026-76423

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.
Configurations

No configuration.

History

16 Sep 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 20:17

Updated : 2026-09-17 12:18


NVD link : CVE-2026-76423

Mitre link : CVE-2026-76423

CVE.ORG link : CVE-2026-76423


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing