Executive Summary
CVE-2026-76433 is a directory traversal flaw in the client provisioning download feature of Cisco Identity Services Engine and Cisco ISE Passive Identity Connector that lets an unauthenticated, remote attacker read protected files on the appliance by sending a crafted request. Because ISE frequently sits at the IT/OT boundary enforcing network access control for plant and substation assets, file disclosure here can hand an attacker the configuration and credential material used to govern who reaches your process network.
Technical Exposure Breakdown
The vulnerable component is the provisioning resource request handler that services client provisioning downloads. According to the grounding data, the defect is insufficient validation of directory traversal character sequences in a user-supplied path. When the software processes a provisioning resource request, it does not properly normalize or restrict the requested path, so sequences that walk up and out of the intended download directory are honored.
The attack vector is network-based and requires no authentication. An attacker reaches the provisioning download service over the same interface that endpoints use to pull posture and provisioning content, then substitutes a traversal path to read files outside the sanctioned resource directory. The published CVSS score is 5.3, which reflects a confidentiality-only impact with no integrity or availability effect and no privilege requirement. That score understates the downstream risk in environments where the exposed files include policy configuration, certificates, or other sensitive operational data.
Affected software per the grounding data covers Cisco Identity Services Engine versions 3.1.0 through 3.3.0 and Cisco Identity Services Engine Passive Identity Connector versions 3.1.0 through 3.3.0. Patch status is listed as unknown in our data set. Operators should treat any 3.1.0 through 3.3.0 deployment of either product as in scope until a vendor fixed release is confirmed against their specific build.
OT Impact and Compliance Risk
ISE is not an industrial controller, but in many utilities and manufacturers it is the authentication and authorization layer deciding which devices and users traverse into the OT zone. A file read on that appliance is reconnaissance that accelerates lateral movement. Disclosure of access policy structure, endpoint inventory, or trust material lets an attacker craft a path into the process network that looks like a legitimate, provisioned endpoint.
From a compliance standpoint, an ISE instance supporting electronic access control to a BES Cyber System is a candidate Electronic Access Control or Monitoring System under NERC CIP, which drags it into CIP-005 and CIP-007 obligations for access management and patch evaluation. Under IEC 62443, this is a conduit and zone-boundary control whose compromise weakens the segmentation assumptions the whole architecture rests on. Pipeline operators under TSA SD-02C and water utilities under AWIA 2018 should likewise account for access-control infrastructure in their identification of critical cyber systems, since a boundary authenticator failing open to information disclosure undercuts the segmentation those mandates expect.
Compensating Controls
Do not rely on a future patch as your only response, and do not run active scans against a production ISE node without a maintenance window. Aggressive probing of the provisioning service can disrupt endpoint onboarding and, in constrained OT networks, cascade into access failures for field devices that depend on timely posture checks.
- Restrict reachability of the client provisioning download service to the specific VLANs and address ranges that legitimately require provisioning. If OT endpoints do not use client provisioning, the service should not be reachable from OT segments at all.
- Place the provisioning interface behind a reverse proxy or WAF that performs path normalization and rejects traversal sequences before the request reaches ISE.
- Deploy a virtual patch at the network layer. A Suricata rule concept: inspect HTTP request URIs destined for the provisioning download path and alert or drop on encoded and literal traversal patterns such as
../,..%2f, and%2e%2e%2fin the user-supplied path parameter. Tune against known-good provisioning URIs to avoid breaking legitimate downloads. - Rotate certificates and any secrets that could be exposed through file read, and audit ISE file access logs for anomalous download requests referencing unexpected paths.
BreachSpider Intel
BreachSpider tracks exploitation signals and patch availability for CVE-2026-76433 and other boundary access-control exposures affecting OT environments. Monitor the advisory and KEV program status through BreachSpider.