[CIVN-2026-0463] Cisco Identity Services Engine Vulnerabilities

By Published On: September 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Cisco Identity Services Engine Vulnerabilities


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Systems Affected


Cisco Identity Services Engine (ISE)

Cisco ISE Passive Identity Connector (ISE-PIC)

Overview


Multiple vulnerabilities have been reported in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.


Target Audience: 

All IT administrators and individuals responsible for maintaining and updating in Software.


Risk Assessment:

High risk of data manipulation and service disruption.


Impact Assessment:

Potential impact on confidentiality, integrity, and availability of the system.


Description


1. Authentication Bypass Vulnerability ( CVE-2026-76423   )


This vulnerability exists due to REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port.

Successful exploitation of this vulnerability could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.


2.  Arbitrary File Access Vulnerability ( CVE-2026-76424   )


This vulnerability exists due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path.

Successful exploitation of this vulnerability could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device.


3.  SQL Injection Vulnerability ( CVE-2026-76425   CVE-2026-76426   CVE-2026-76428   )


These vulnerabilities exist due to insufficient validation of certain parameters that are concatenated directly into an SQL query, certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint.

Successful exploitation of this vulnerability could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks.


4.  External Entity Injection Vulnerability ( CVE-2026-76427   )


This vulnerability exists due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface.

Successful exploitation of this vulnerability could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device.


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ


CVE Name

CVE-2026-76423

CVE-2026-76424

CVE-2026-76425

CVE-2026-76426

CVE-2026-76428

CVE-2026-76427




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtTWEACgkQ3jCgcSdc

ys89FhAAg5I52fzxPIbLiN4LZ8oC3GxlPZ7jlZK88X4DeFQcVZIam/Vk1wWJMZgc

gqeYDsX142TzTQ2qhXkx5lXlEdyLpYpUlBJWgNSe7pbP3aC1vlLSNnXB0rNNnCc4

hqSsQCXu1ZvHobPnpClOLUuHgMsUH4hHsuwDR7V9pFcBT+WolQuMJdqFEhIRTick

W9Jz6YgQa97DEvSvClWpklV8PyXHMRdZvuO4LvygNxjGuqGanmp3S7o4lTeEJCKd

Qwbvc1MuEULbTfZ01j1vgEu0MH9jZHqBLU90vO3yFg2flvwLRydKToyy/ffrgK9T

1oFurPtBdr+KTtlGhCayQqd47uBvIqLpI/CrOl6cuE6wCPE/ypLPbz8z4QSUOmDG

xZrTwexXt7BnAzzQEP2Nv/S8sFvtbTa6CS7dZ4GIQc7c4fR2RClR4axHU/0syHWJ

oIK23biNuqJoLd322LkuYEzjZIz6PtEHejn3pg7mdRViMFSe4dSUaiGK6fNh31Sk

NnQ29Zk8aZGYjdwD2JTI34Cb7SValxnvDwzuH5dMc1bPjOXH5qDBQ3gFHDXftRn7

XKSMRbdr5QEDcDIbHQwy/uRwNt+aa/UmAU9u26Rh7JCl3i7bZ0Ea4HK0UCxkJuQl

zYUvL8DlbOUrJE59NePpieGYLU12VxU3jJTPJFwHrP9QavUwIIg=

=TmKK

—–END PGP SIGNATURE—–

Share this article