Loading market data...
← Back to CVE feed

CVE-2026-76460

CRITICAL CVSS 10.0 View on NVD ↗

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

cisco/identity_services_engine cisco/identity_services_engine_passive_identity_connector
Published: Sep 16, 2026 21:17 UTC Modified: Sep 17, 2026 12:46 UTC