CVE-2026-76431

MEDIUM

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and dire...

CVSS 3.14.9
EPSS1.2%
Percentile67th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, high privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A medium severity vulnerability (CVE-2026-76431) affects the target system. A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulner...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-76431?
A medium severity vulnerability (CVE-2026-76431) affects the target system. A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulner...
What is the CVSS score for CVE-2026-76431?
CVE-2026-76431 has CVSS 4.9 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N. EPSS: 1.2%.
Is CVE-2026-76431 actively exploited?
No confirmed active exploitation of CVE-2026-76431 as of 2026-09-29.
How do I remediate CVE-2026-76431?
Apply vendor patches for CVE-2026-76431. Monitor the vendor advisories.
Vulnerability Details
CVE IDCVE-2026-76431
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Published2026-09-16
Last Modified2026-09-28
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of directory traversal character sequences in a user-supplied file path before the request is validated. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to delete arbitrary files and directories on the underlying operating system of the affected device.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Cisco Identity Services Engine 3.3.0 3.4.0 3.5.0 ≥ 3.1.0, < 3.3.0
Cisco Identity Services Engine Passive Identity Connector 3.3.0 3.4.0 ≥ 3.1.0, < 3.3.0
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 14 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →