CVE-2026-76444: Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need valid Cisco ISE credentials to exploit this issue?
No. The vulnerability can be exploited remotely without authentication by sending a crafted request to the affected device.
What is the likely impact of successful exploitation?
A successful attack can disclose sensitive configuration information. The provided severity vector indicates confidentiality impact only, with no stated integrity or availability impact.
Which products are identified as affected?
The affected software listed is Cisco Identity Services Engine (ISE) and Cisco Identity Services Engine-PIC (ISE-PIC).