CVE-2026-76433 Overview
Cisco disclosed a directory traversal vulnerability in the client provisioning download feature of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw allows an unauthenticated, remote attacker to read protected files on an affected device by sending crafted requests to the provisioning download service. The weakness maps to [CWE-22] (Improper Limitation of a Pathname to a Restricted Directory).
Critical Impact
Unauthenticated remote attackers can retrieve protected files from Cisco ISE and ISE-PIC deployments, potentially exposing sensitive configuration or credential material.
Affected Products
- Cisco Identity Services Engine (ISE)
- Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
- Refer to the Cisco Security Advisory for specific fixed release versions
Discovery Timeline
- 2026-09-16 - CVE-2026-76433 published to NVD
- 2026-09-17 - Last updated in NVD database
Technical Details for CVE-2026-76433
Vulnerability Analysis
The vulnerability resides in the client provisioning download feature of Cisco ISE and ISE-PIC. The provisioning service accepts user-supplied path values when handling resource requests. The service fails to normalize or validate directory traversal sequences such as ../ before resolving the requested file.
An unauthenticated attacker can craft an HTTP request containing traversal sequences to escape the intended provisioning directory. The resulting response returns file contents from arbitrary paths on the appliance. Because the endpoint requires no credentials, exposure extends to any network location that can reach the provisioning port.
Root Cause
The root cause is insufficient input validation on the file path parameter processed by the provisioning download handler. The handler treats the user-controlled path as trusted and passes it to file resolution logic without canonicalization checks. This category of flaw is tracked under [CWE-22].
Attack Vector
Exploitation requires network access to the provisioning endpoint on an affected ISE or ISE-PIC deployment. The attacker sends a single crafted HTTP request that embeds traversal sequences in the resource path. No authentication, user interaction, or elevated privileges are required. The impact is limited to file read, so integrity and availability of the appliance are not directly affected by this specific issue.
See the Cisco Security Advisory for protocol-level details.
Detection Methods for CVE-2026-76433
Indicators of Compromise
- HTTP requests to the ISE client provisioning download endpoint containing ../, ..\, or URL-encoded variants such as %2e%2e%2f.
- Access log entries showing successful responses for provisioning resource paths that resolve outside the expected provisioning directory.
- Unusual outbound file retrievals from ISE or ISE-PIC nodes correlated with unauthenticated sessions.
Detection Strategies
- Inspect web server and application access logs on ISE and ISE-PIC nodes for traversal patterns targeting the provisioning download URI.
- Deploy WAF or IPS signatures that flag directory traversal payloads directed at the ISE management and provisioning interfaces.
- Baseline expected provisioning resource requests and alert on any request whose resolved path lies outside the provisioning root.
Monitoring Recommendations
- Forward ISE and ISE-PIC access and application logs to a centralized SIEM for correlation and long-term retention.
- Monitor for repeated 200-response requests to the provisioning endpoint from unauthenticated sources.
- Alert on any file retrieval that returns configuration files, certificates, or credential stores through the provisioning service.
How to Mitigate CVE-2026-76433
Immediate Actions Required
- Review the Cisco Security Advisory and identify affected ISE and ISE-PIC versions in your environment.
- Apply the fixed Cisco ISE release as soon as it is available for your deployment.
- Restrict network exposure of ISE management and provisioning interfaces to trusted administrative networks only.
Patch Information
Cisco has published fixed software releases through the referenced security advisory. Consult the advisory for the specific fixed train that applies to your ISE or ISE-PIC deployment and follow Cisco's documented upgrade procedure.
Workarounds
- Place ISE and ISE-PIC nodes behind network access controls that limit reachability of the provisioning service to required client subnets.
- Apply intrusion prevention signatures that block directory traversal sequences in requests to the provisioning download endpoint.
- Monitor for unauthenticated access to the provisioning service and terminate suspicious sessions.
# Example ACL concept: restrict provisioning port to trusted subnets
# Replace <provisioning_port> and <trusted_subnet> with values from your environment
access-list ISE_PROVISIONING permit tcp <trusted_subnet> host <ise_node> eq <provisioning_port>
access-list ISE_PROVISIONING deny tcp any host <ise_node> eq <provisioning_port>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.