
[CIVN-2026-0463] Cisco Identity Services Engine Vulnerabilities
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cisco Identity Services Engine Vulnerabilities
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Systems Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Overview
Multiple vulnerabilities have been reported in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating in Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
1. Authentication Bypass Vulnerability ( CVE-2026-76423 )
This vulnerability exists due to REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port.
Successful exploitation of this vulnerability could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.
2. Arbitrary File Access Vulnerability ( CVE-2026-76424 )
This vulnerability exists due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path.
Successful exploitation of this vulnerability could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device.
3. SQL Injection Vulnerability ( CVE-2026-76425 CVE-2026-76426 CVE-2026-76428 )
These vulnerabilities exist due to insufficient validation of certain parameters that are concatenated directly into an SQL query, certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint.
Successful exploitation of this vulnerability could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks.
4. External Entity Injection Vulnerability ( CVE-2026-76427 )
This vulnerability exists due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface.
Successful exploitation of this vulnerability could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
CVE Name
CVE-2026-76423
CVE-2026-76424
CVE-2026-76425
CVE-2026-76426
CVE-2026-76428
CVE-2026-76427
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtTWEACgkQ3jCgcSdc
ys89FhAAg5I52fzxPIbLiN4LZ8oC3GxlPZ7jlZK88X4DeFQcVZIam/Vk1wWJMZgc
gqeYDsX142TzTQ2qhXkx5lXlEdyLpYpUlBJWgNSe7pbP3aC1vlLSNnXB0rNNnCc4
hqSsQCXu1ZvHobPnpClOLUuHgMsUH4hHsuwDR7V9pFcBT+WolQuMJdqFEhIRTick
W9Jz6YgQa97DEvSvClWpklV8PyXHMRdZvuO4LvygNxjGuqGanmp3S7o4lTeEJCKd
Qwbvc1MuEULbTfZ01j1vgEu0MH9jZHqBLU90vO3yFg2flvwLRydKToyy/ffrgK9T
1oFurPtBdr+KTtlGhCayQqd47uBvIqLpI/CrOl6cuE6wCPE/ypLPbz8z4QSUOmDG
xZrTwexXt7BnAzzQEP2Nv/S8sFvtbTa6CS7dZ4GIQc7c4fR2RClR4axHU/0syHWJ
oIK23biNuqJoLd322LkuYEzjZIz6PtEHejn3pg7mdRViMFSe4dSUaiGK6fNh31Sk
NnQ29Zk8aZGYjdwD2JTI34Cb7SValxnvDwzuH5dMc1bPjOXH5qDBQ3gFHDXftRn7
XKSMRbdr5QEDcDIbHQwy/uRwNt+aa/UmAU9u26Rh7JCl3i7bZ0Ea4HK0UCxkJuQl
zYUvL8DlbOUrJE59NePpieGYLU12VxU3jJTPJFwHrP9QavUwIIg=
=TmKK
—–END PGP SIGNATURE—–


