CVE-2026-76433: Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the software processes provisioning resource requests. An attacker could exploit this vulnerability by sending a crafted request to the provisioning download service. A successful exploit could allow the attacker to access protected files without authentication, potentially exposing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No authentication or user interaction is required. An attacker can send a crafted request remotely to the provisioning download service.
Which deployments are exposed?
Cisco ISE and Cisco ISE-PIC deployments are affected where the client provisioning download feature processes provisioning resource requests. The provided information does not identify specific affected versions or configuration conditions.
What could an attacker obtain?
A successful exploit can allow access to protected files on the affected device. This may expose sensitive information, although the specific files and data types are not identified.