Skip to main content
Vulnerability Database/CVE-2026-76433

CVE-2026-76433: Cisco ISE Path Traversal Vulnerability

CVE-2026-76433 is a path traversal vulnerability in Cisco Identity Services Engine that enables unauthenticated attackers to access protected files. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-76433 Overview

Cisco disclosed a directory traversal vulnerability in the client provisioning download feature of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw allows an unauthenticated, remote attacker to read protected files on an affected device by sending crafted requests to the provisioning download service. The weakness maps to [CWE-22] (Improper Limitation of a Pathname to a Restricted Directory).

Critical Impact

Unauthenticated remote attackers can retrieve protected files from Cisco ISE and ISE-PIC deployments, potentially exposing sensitive configuration or credential material.

Affected Products

  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
  • Refer to the Cisco Security Advisory for specific fixed release versions

Discovery Timeline

  • 2026-09-16 - CVE-2026-76433 published to NVD
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-76433

Vulnerability Analysis

The vulnerability resides in the client provisioning download feature of Cisco ISE and ISE-PIC. The provisioning service accepts user-supplied path values when handling resource requests. The service fails to normalize or validate directory traversal sequences such as ../ before resolving the requested file.

An unauthenticated attacker can craft an HTTP request containing traversal sequences to escape the intended provisioning directory. The resulting response returns file contents from arbitrary paths on the appliance. Because the endpoint requires no credentials, exposure extends to any network location that can reach the provisioning port.

Root Cause

The root cause is insufficient input validation on the file path parameter processed by the provisioning download handler. The handler treats the user-controlled path as trusted and passes it to file resolution logic without canonicalization checks. This category of flaw is tracked under [CWE-22].

Attack Vector

Exploitation requires network access to the provisioning endpoint on an affected ISE or ISE-PIC deployment. The attacker sends a single crafted HTTP request that embeds traversal sequences in the resource path. No authentication, user interaction, or elevated privileges are required. The impact is limited to file read, so integrity and availability of the appliance are not directly affected by this specific issue.

See the Cisco Security Advisory for protocol-level details.

Detection Methods for CVE-2026-76433

Indicators of Compromise

  • HTTP requests to the ISE client provisioning download endpoint containing ../, ..\, or URL-encoded variants such as %2e%2e%2f.
  • Access log entries showing successful responses for provisioning resource paths that resolve outside the expected provisioning directory.
  • Unusual outbound file retrievals from ISE or ISE-PIC nodes correlated with unauthenticated sessions.

Detection Strategies

  • Inspect web server and application access logs on ISE and ISE-PIC nodes for traversal patterns targeting the provisioning download URI.
  • Deploy WAF or IPS signatures that flag directory traversal payloads directed at the ISE management and provisioning interfaces.
  • Baseline expected provisioning resource requests and alert on any request whose resolved path lies outside the provisioning root.

Monitoring Recommendations

  • Forward ISE and ISE-PIC access and application logs to a centralized SIEM for correlation and long-term retention.
  • Monitor for repeated 200-response requests to the provisioning endpoint from unauthenticated sources.
  • Alert on any file retrieval that returns configuration files, certificates, or credential stores through the provisioning service.

How to Mitigate CVE-2026-76433

Immediate Actions Required

  • Review the Cisco Security Advisory and identify affected ISE and ISE-PIC versions in your environment.
  • Apply the fixed Cisco ISE release as soon as it is available for your deployment.
  • Restrict network exposure of ISE management and provisioning interfaces to trusted administrative networks only.

Patch Information

Cisco has published fixed software releases through the referenced security advisory. Consult the advisory for the specific fixed train that applies to your ISE or ISE-PIC deployment and follow Cisco's documented upgrade procedure.

Workarounds

  • Place ISE and ISE-PIC nodes behind network access controls that limit reachability of the provisioning service to required client subnets.
  • Apply intrusion prevention signatures that block directory traversal sequences in requests to the provisioning download endpoint.
  • Monitor for unauthenticated access to the provisioning service and terminate suspicious sessions.
bash
# Example ACL concept: restrict provisioning port to trusted subnets
# Replace <provisioning_port> and <trusted_subnet> with values from your environment
access-list ISE_PROVISIONING permit tcp <trusted_subnet> host <ise_node> eq <provisioning_port>
access-list ISE_PROVISIONING deny   tcp any host <ise_node> eq <provisioning_port>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.