CVE-2026-76424
largePath traversal in Cisco ISE REST API enables authenticated root RCE
Cisco Identity Services Engine (ISE) contains a path traversal flaw (CWE-23) in its REST API caused by insufficient validation of file operations. An attacker who already holds valid administrative credentials can send an API request uploading a file with a crafted path, allowing the file to be written to arbitrary locations on the device. Successful exploitation lets the attacker upload files anywhere on the appliance and execute arbitrary commands with root privileges, giving full compromise of the ISE deployment. Because high privileges are required, the flaw is rated CVSS 3.1 7.2 (High) with AV:N/AC:L/PR:H. It is not currently listed in CISA's KEV catalog and no public proof-of-concept or in-the-wild exploitation is known.
What to do: Upgrade ISE to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-76424. Until patched, restrict access to the ISE REST API to trusted management networks, audit privileged/administrative accounts for compromise, and review API logs for file-upload requests containing path traversal characters (e.g., ../ sequences).
| Cisco Identity Services Engine (ISE) REST API | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
- Weakness
- CWE-23
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.