A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. (CVE-2026-76424)
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) allows an authenticated remote attacker with administrative credentials to upload or copy arbitrary files on the device. This occurs due to insufficient validation of file operations, enabling crafted path uploads. Successful exploitation could lead to arbitrary command execution as root on the affected device. The vulnerability has a high severity score of 7.2 (CVSS 3.1). No affected versions or patch information are provided.
AI Analysis
Technical Summary
CVE-2026-76424 describes a vulnerability in the REST API of Cisco ISE where insufficient validation of file operations permits an authenticated attacker with administrative privileges to upload files to arbitrary locations. By uploading a file with a crafted path, the attacker could execute arbitrary commands as root on the device. Exploitation requires valid administrative credentials. The vulnerability is classified under CWE-23 (Relative Path Traversal). The CVSS v3.1 base score is 7.2, indicating high severity with network attack vector, low attack complexity, high privileges required, no user interaction, and impacts to confidentiality, integrity, and availability.
Potential Impact
An attacker with valid administrative credentials can upload files to arbitrary locations on the affected Cisco ISE device and execute arbitrary commands as root. This compromises the confidentiality, integrity, and availability of the device, potentially leading to full system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability requires administrative credentials, limiting administrative access and monitoring for suspicious activity may reduce risk until a fix is available.
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. (CVE-2026-76424)
Description
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) allows an authenticated remote attacker with administrative credentials to upload or copy arbitrary files on the device. This occurs due to insufficient validation of file operations, enabling crafted path uploads. Successful exploitation could lead to arbitrary command execution as root on the affected device. The vulnerability has a high severity score of 7.2 (CVSS 3.1). No affected versions or patch information are provided.
CVSS v3.1
Score 7.2high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76424 describes a vulnerability in the REST API of Cisco ISE where insufficient validation of file operations permits an authenticated attacker with administrative privileges to upload files to arbitrary locations. By uploading a file with a crafted path, the attacker could execute arbitrary commands as root on the device. Exploitation requires valid administrative credentials. The vulnerability is classified under CWE-23 (Relative Path Traversal). The CVSS v3.1 base score is 7.2, indicating high severity with network attack vector, low attack complexity, high privileges required, no user interaction, and impacts to confidentiality, integrity, and availability.
Potential Impact
An attacker with valid administrative credentials can upload files to arbitrary locations on the affected Cisco ISE device and execute arbitrary commands as root. This compromises the confidentiality, integrity, and availability of the device, potentially leading to full system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability requires administrative credentials, limiting administrative access and monitoring for suspicious activity may reduce risk until a fix is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9mjp-cphq-5x57
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76424"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aab49a255bf5e2cf5991b83
Added to database: 09/17/2026, 02:00:02 UTC
Last enriched: 09/17/2026, 02:36:53 UTC
Last updated: 09/17/2026, 05:01:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.