CVE-2026-76431: Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of directory traversal character sequences in a user-supplied file path before the request is validated. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to delete arbitrary files and directories on the underlying operating system of the affected device.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to reach the web-based management interface and possess valid administrative credentials. Unauthenticated users are not described as able to exploit it.
What is the potential impact of successful exploitation?
A successful attacker can delete arbitrary files and directories on the underlying operating system of an affected device. The provided impact information indicates integrity impact, with no stated confidentiality or availability impact.
What attacker action triggers the vulnerability?
The attacker sends a crafted request containing directory traversal character sequences in a user-supplied file path to the web-based management interface. The issue is caused by improper validation of those sequences before the request is validated.
Are both Cisco ISE and Cisco ISE-PIC in scope?
Yes. The affected software listed includes Cisco ISE and Cisco ISE-PIC.