Skip to content

Build2 publishers2 min readPublished

A crafted request to one Cisco ISE API endpoint reaches root without a credential

Cisco's PSIRT says CVE-2026-76460 is being exploited, and the company has published no workaround, so the fix is a branch-specific patch. ISE 3.0 is past End of Software Maintenance and gets a migration.

The Engineer · Build desk

Illustration accompanying A crafted request to one Cisco ISE API endpoint reaches root without a credential

What happened

  • Cisco disclosed on September 16, 2026 that CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine, lets an unauthenticated remote attacker gain root privileges on the appliance.
  • Cisco's PSIRT confirmed the flaw is being exploited in the wild, and the company says it found the defect while working a Technical Assistance Center support case.
  • A crafted network request to the exposed endpoint executes commands as root without a credential, and it never passes through the web management interface.
  • Affected products are Cisco ISE and ISE-PIC in all device configurations, across releases 3.1 through 3.5.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Cisco's guidance offers one pre-patch control: an infrastructure access control list keeping untrusted traffic away from ISE management interfaces. That is a network change.
  • decision Anyone still running ISE 3.0 has to pick a supported branch and schedule a migration while exploitation is confirmed, and that decision cannot be made inside a patch window.
  • exposure Root on ISE puts the attacker in charge of network admission policy for everything that trusts it, so access rules and internal subnets become reachable from an unauthenticated network position.
  • exposure Because the advisory says attackers can erase log entries, clean logs do not clear an appliance, and the dummyuser account entries Cisco flags are the detection defenders are handed.

"Insufficient authentication control on an API endpoint" is the entire technical description in Cisco's advisory [4]. Read literally, that means the endpoint answers before it establishes who is calling. The request never goes through the web management interface, so the admin roles and whatever MFA sits in front of the ISE web console never see it [5].

Cisco found the defect while working a Technical Assistance Center support case, and the dev.to write-up takes that provenance as a sign of real-world activity [3]. A support case is an unusual way to find your own CVSS 10.0.

The fixes are branch-specific, and there are five of them: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4 [9][21]. Cisco lists no patch for the 3.0 line, because that release reached End of Software Maintenance, and Cisco advises customers on it to migrate to a supported release that includes the fix [13]. Cisco's own remediation language is blunt: the advisory "strongly recommends that customers upgrade to the fixed software indicated in this advisory" [14], and it treats any workaround or mitigation as a temporary solution until that upgrade happens [19].

Cisco's PSIRT validates only the affected and fixed release information documented in the advisory [15]. The write-up's reference list also includes a CISA alert adding two vulnerabilities to the Known Exploited Vulnerabilities catalog on September 16, 2026 [20].

The exposure figure in circulation comes from a scanner. The dev.to write-up reports 4,051 instances worldwide for the product fingerprint app="Cisco ISE", and 0 for a filter on vul.cve="CVE-2026-76460", which it attributes to ZoomEye not yet indexing the new identifier [16][17]. The same write-up says the product count describes assets matching the fingerprint and does not confirm that every one is vulnerable [18]. For it to be a count of exploitable targets, every match would have to be a live ISE on 3.1 through 3.5, unpatched, with the vulnerable endpoint reachable from wherever the scanner sat [7].

What to watch

  • A CISA remediation due date attached to the KEV entry would turn vendor advice into a fixed clock for federal ISE operators.
  • If Cisco adds a workaround or explicit ACL guidance to the advisory, the pre-patch options change for estates that cannot upgrade this week.
  • A version-resolved scan count that separates patched from unpatched ISE hosts would replace the 4,051 fingerprint figure with something usable.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories