CVE-2026-76460 Overview
CVE-2026-76460 is an authentication bypass vulnerability in an API of Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector. An unauthenticated, remote attacker can send a crafted request to an affected API endpoint and gain unauthorized access to the web-based management interface. The flaw stems from insufficient authentication controls on the exposed API endpoint and is classified under [CWE-648] (Incorrect Use of Privileged APIs). CISA has added CVE-2026-76460 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation.
Critical Impact
Unauthenticated remote attackers can bypass authentication on Cisco ISE, gaining administrative access to identity, authentication, and network access policy infrastructure.
Affected Products
- Cisco Identity Services Engine versions 3.1.0 through 3.5.0 (including all listed patch levels)
- Cisco Identity Services Engine Passive Identity Connector versions 3.1.0 through 3.5.0 (including all listed patch levels)
- Deployments exposing the ISE web-based management API to reachable networks
Discovery Timeline
- 2026-09-16 - CVE-2026-76460 published to NVD
- 2026-09-17 - Last updated in NVD database
Technical Details for CVE-2026-76460
Vulnerability Analysis
Cisco Identity Services Engine centralizes network authentication, authorization, and accounting (AAA), including 802.1X, TACACS+, and RADIUS services. A specific API endpoint in the ISE web-based management interface does not enforce authentication before processing requests. An attacker who reaches the endpoint over the network can invoke privileged functionality without credentials. Successful exploitation yields access equivalent to an authenticated administrator of the management interface, enabling manipulation of policies that govern network access across the enterprise.
Root Cause
The root cause is insufficient authentication control on an ISE API endpoint, mapped to [CWE-648]. The endpoint accepts and processes crafted requests without validating that the caller has a valid session or credential. Because the API is reachable through the same management channel used by administrators, authentication is the sole boundary between an anonymous network client and privileged operations.
Attack Vector
Exploitation requires only network reachability to the ISE management interface. No user interaction, credentials, or prior access are required. An attacker sends a crafted HTTP request to the vulnerable API endpoint, which processes the request as if it originated from an authorized session. From this initial foothold, attackers can pivot to configuration changes, credential harvesting, and lateral movement into any environment governed by ISE-issued policies.
No public proof-of-concept has been published at this time. Refer to the Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5 for authoritative technical detail.
Detection Methods for CVE-2026-76460
Indicators of Compromise
- Unauthenticated HTTP requests to ISE management API endpoints originating from unexpected source addresses.
- New or modified administrator accounts, RADIUS/TACACS+ clients, or authorization policies that do not correlate with change tickets.
- Unexpected policy pushes, endpoint reclassifications, or authorization rule changes in ISE audit logs.
- Session records showing privileged operations without a preceding successful login event.
Detection Strategies
- Review ISE administrative audit logs for API calls that lack an associated authenticated session identifier.
- Correlate web server access logs on ISE nodes with authentication events to identify privileged actions from unauthenticated contexts.
- Alert on HTTP requests to ISE management endpoints from source networks outside the approved administrator jump-host range.
Monitoring Recommendations
- Forward ISE syslog, admin audit, and web server logs to a centralized SIEM for continuous correlation.
- Baseline normal administrator API usage patterns and alert on volume, timing, or source-address deviations.
- Monitor downstream network devices for unexpected AAA policy changes originating from ISE.
How to Mitigate CVE-2026-76460
Immediate Actions Required
- Apply the fixed software releases identified in the Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5 as the primary remediation.
- Restrict network reachability to the ISE management interface to a small set of trusted administrator hosts and jump servers.
- Rotate ISE administrator credentials, API keys, and any shared secrets that may have been exposed on affected deployments.
- Review ISE audit logs and downstream AAA changes for evidence of exploitation given CISA KEV listing.
Patch Information
Cisco has released fixed software for affected ISE and ISE Passive Identity Connector releases in the 3.1, 3.2, 3.3, 3.4, and 3.5 trains. Consult the Cisco Security Advisory for the specific fixed patch level per release train and upgrade guidance. This vulnerability is tracked in the CISA Known Exploited Vulnerabilities Catalog, which mandates prompt federal remediation timelines.
Workarounds
- Enforce management-plane access control lists that permit only known administrator source addresses to reach the ISE web and API interfaces.
- Place ISE administrative interfaces behind a dedicated out-of-band management network segmented from user and server VLANs.
- Use a reverse proxy or WAF to filter unauthenticated requests to sensitive ISE API paths until patches are deployed.
# Example ACL restricting ISE management access to an admin jump-host subnet
ip access-list extended ISE-MGMT-ACL
permit tcp 10.10.5.0 0.0.0.255 host <ISE-MGMT-IP> eq 443
deny tcp any host <ISE-MGMT-IP> eq 443 log
permit ip any any
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
