External risk intelligence

Cisco ISE REST API Administrative Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-76423

The vulnerability exists in a REST API associated with Cisco ISE, a product often deployed to manage identity and network access. These services frequently act as gateways or centralized infrastructure components, and the nature of this API service makes it a target that is commonly reachable or intentionally exposed in network architectures requiring remote management or identity integration.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability affecting Cisco's Identity Services Engine (ISE) and ISE-PIC products allows unauthenticated attackers to gain administrative control by exploiting an exposed REST API with weak authorization. This could enable attackers to read and modify critical network access and identity configurations.

  • Unauthenticated API access grants administrative control.
  • Essential for network access and identity management.
  • Confirm relevance to our network infrastructure.

Attack Path

How an attacker could exploit the issue

An attacker could initiate an attack by targeting the exposed REST API of Cisco ISE or Cisco ISE-PIC. This API, lacking sufficient authorization, allows an unauthenticated, remote attacker to send a specially crafted HTTP request. Successful exploitation grants administrative privileges, enabling the attacker to view and alter configuration and identity data.

  • Unauthenticated remote access required.
  • Triggered via crafted HTTP request.
  • Allows full administrative control.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated, remote attacker could gain administrative access to a Cisco ISE device when supported by the advisory. This is possible because the REST API web service lacks sufficient authorization checks, allowing a crafted HTTP request to exploit the vulnerability. If successful, an attacker could read and modify ISE configuration and identity data with administrative privileges.

  • Administrative access to devices.
  • Sending a crafted HTTP request.
  • Configuration and identity data modified.

Operational Fix

Recommended remediation, mitigation, and detection steps

The criticality of this vulnerability requires immediate attention from network and security teams, potentially in coordination with Cisco vendor management. The first practical step involves identifying all Cisco ISE and ISE-PIC instances within the environment, confirming their external reachability and business criticality, and then engaging the accountable owners to plan for remediation or risk reduction.

  • Network and Security Teams own the issue.
  • Verify external reachability and business criticality.
  • Plan remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cisco ISE and its role in my network?

Cisco Identity Services Engine (ISE) is a platform that controls network access and identity. It acts as a gatekeeper, deciding which users and devices can connect to your infrastructure, enforcing security policies, and managing authentication for both wired and wireless environments.

What does CWE-290 mean for CVE-2026-76423?

CWE-290 refers to Authentication Bypass by Spoofing. In the context of CVE-2026-76423, it means the software fails to properly verify the identity of the user requesting access. Because the REST API lacks sufficient authorization checks, the system incorrectly treats an unauthenticated request as trusted, allowing the attacker to bypass normal security gatekeeping.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specially crafted HTTP request directly to the REST API port used by Cisco ISE or ISE-PIC. No pre-existing credentials or login sessions are required to initiate this process. The vulnerability does not require physical access to the hardware; however, the API must be reachable by the attacker's network traffic.

Do I need to worry if my device is on the internal network?

While the Halo Surface Signal indicates this vulnerability is classified as external due to its network-based nature, you should still evaluate your specific setup. Even if a device is not directly on the internet, it may be accessible to internal actors or other segments of your network. If the API port is reachable from any untrusted or broader network segment, you should consider it a potential target.

When should I start addressing this vulnerability?

You should begin by immediately cataloging all instances of Cisco ISE and ISE-PIC within your organization. Prioritize those that are accessible via the network to understand your potential exposure. Work with your network infrastructure teams to confirm the business criticality of these specific instances and coordinate with your vendor contacts to align on patch management.

References