Executive Summary

CVE-2026-76432 is a directory traversal flaw in the web-based management interface of Cisco Identity Services Engine (ISE) and the Passive Identity Connector (ISE-PIC) that lets an authenticated administrator write arbitrary files to arbitrary locations on the underlying appliance. The vulnerability carries a CVSS score of 4.9 and is not currently listed in the known exploited vulnerability catalog, but in OT environments where ISE acts as the enforcement backbone for network access control, an attacker-controlled file write to a security appliance is a staging point for persistence and lateral movement toward the process network.

Technical Exposure Breakdown

Per the grounding data, the flaw exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process. An attacker uploads a crafted file, and because the path is not sanitized, traversal sequences allow the file to land outside the intended upload directory. The vulnerable range covers Cisco Identity Services Engine versions 3.1.0 through 3.3.0 and Cisco Identity Services Engine Passive Identity Connector versions 3.1.0 through 3.3.0.

The precondition is administrative-level privilege on the web management interface. This is not a pre-auth remote exploit, and that distinction matters. The severity rating of 4.9 reflects the high privilege requirement. The relevant OT concern is not an anonymous internet attacker. It is credential compromise, a rogue or coerced insider, or an attacker who has already pivoted far enough to reach the ISE admin plane. In those scenarios, the ability to write files to arbitrary locations on the appliance converts administrative access into a foothold that can outlast credential rotation, because a planted file can act as a backdoor, a modified configuration artifact, or a trigger for later code execution.

Patch status is listed as unknown in the grounding data. Treat the affected versions as exposed until a fixed train is confirmed through your vendor channel and validated in a lab that mirrors your production ISE deployment.

OT Impact and Compliance Risk

ISE is frequently deployed at the IT/OT boundary as the policy decision point for 802.1X, MAB, and TrustSec segmentation that separates corporate traffic from the control network. If the appliance enforcing that segmentation is itself writable by an attacker, the integrity of the entire access control policy is in question. An attacker who can write files on ISE may be positioned to alter authorization logic over time or to establish a covert channel that survives routine maintenance.

Under IEC 62443, this bears directly on SR 1.1 and SR 1.2 identification and authentication controls and on the system integrity requirements in FR 3, since the device providing those controls can have its own integrity undermined. For NERC CIP environments, an ISE appliance inside the Electronic Security Perimeter is typically a Cyber Asset subject to CIP-007 system security management and CIP-010 configuration change monitoring. An arbitrary file write defeats the assumption behind baseline configuration monitoring. For pipeline operators under TSA SD-02C, ISE sits squarely in the network segmentation and access control measures the directive mandates, so its compromise is a reportable concern. Water utilities operating under AWIA 2018 risk and resilience assessments should account for the same dependency where ISE underpins remote access governance.

Compensating Controls

Do not rely on the patch alone. Start by treating the ISE admin interface as a protected enclave. Restrict management access to a dedicated out-of-band administrative network and deny reachability from general IT and from the OT process network. Enforce strong multi-factor authentication on all ISE administrative accounts and audit the full admin account inventory, because this flaw is only reachable with admin privilege.

Enable and forward ISE administrative audit logs and file-system integrity monitoring to a SIEM, and alert on unexpected file creation outside known upload paths. A virtual patch concept at the reverse proxy or inline sensor should reject HTTP upload requests whose file path parameters contain encoded or literal traversal sequences. A Suricata rule concept would inspect POST requests to the ISE management upload endpoints and match on path parameters containing ../, ..%2f, %2e%2e, or backslash equivalents, then alert and drop. Validate any such rule against normal admin traffic before enforcement to avoid breaking legitimate uploads.

Do not run active vulnerability scans against ISE or adjacent control components to confirm exposure. Aggressive scanning of security appliances and industrial endpoints can disrupt services and brick fragile components. Confirm versions passively through configuration records and vendor inventory instead.

BreachSpider Intel

BreachSpider tracks CVE-2026-76432 and related access control appliance exposures across OT environments for continuous monitoring and advisory updates.