ZeroHour

CVE-2026-76424

large

Path traversal in Cisco ISE REST API enables authenticated root RCE

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

Cisco Identity Services Engine (ISE) contains a path traversal flaw (CWE-23) in its REST API caused by insufficient validation of file operations. An attacker who already holds valid administrative credentials can send an API request uploading a file with a crafted path, allowing the file to be written to arbitrary locations on the device. Successful exploitation lets the attacker upload files anywhere on the appliance and execute arbitrary commands with root privileges, giving full compromise of the ISE deployment. Because high privileges are required, the flaw is rated CVSS 3.1 7.2 (High) with AV:N/AC:L/PR:H. It is not currently listed in CISA's KEV catalog and no public proof-of-concept or in-the-wild exploitation is known.

What to do: Upgrade ISE to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-76424. Until patched, restrict access to the ISE REST API to trusted management networks, audit privileged/administrative accounts for compromise, and review API logs for file-upload requests containing path traversal characters (e.g., ../ sequences).

Affected
Cisco Identity Services Engine (ISE) REST API
Estimated exposure
large≈10,000–100,000 enterprise ISE deployments (appliances/VMs) worldwide, though only a fraction expose the REST API beyond trusted management networks — Cisco ISE is the vendor's flagship network access control/identity platform widely deployed by large enterprises, universities, and government networks, so its installed base is plausibly in the tens of thousands of devices, but exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.