Executive Summary

CVE-2026-76433 is a directory traversal flaw in the client provisioning download feature of Cisco Identity Services Engine and Cisco ISE Passive Identity Connector that lets an unauthenticated, remote attacker read protected files on the appliance by sending a crafted request. Because ISE frequently sits at the IT/OT boundary enforcing network access control for plant and substation assets, file disclosure here can hand an attacker the configuration and credential material used to govern who reaches your process network.

Technical Exposure Breakdown

The vulnerable component is the provisioning resource request handler that services client provisioning downloads. According to the grounding data, the defect is insufficient validation of directory traversal character sequences in a user-supplied path. When the software processes a provisioning resource request, it does not properly normalize or restrict the requested path, so sequences that walk up and out of the intended download directory are honored.

The attack vector is network-based and requires no authentication. An attacker reaches the provisioning download service over the same interface that endpoints use to pull posture and provisioning content, then substitutes a traversal path to read files outside the sanctioned resource directory. The published CVSS score is 5.3, which reflects a confidentiality-only impact with no integrity or availability effect and no privilege requirement. That score understates the downstream risk in environments where the exposed files include policy configuration, certificates, or other sensitive operational data.

Affected software per the grounding data covers Cisco Identity Services Engine versions 3.1.0 through 3.3.0 and Cisco Identity Services Engine Passive Identity Connector versions 3.1.0 through 3.3.0. Patch status is listed as unknown in our data set. Operators should treat any 3.1.0 through 3.3.0 deployment of either product as in scope until a vendor fixed release is confirmed against their specific build.

OT Impact and Compliance Risk

ISE is not an industrial controller, but in many utilities and manufacturers it is the authentication and authorization layer deciding which devices and users traverse into the OT zone. A file read on that appliance is reconnaissance that accelerates lateral movement. Disclosure of access policy structure, endpoint inventory, or trust material lets an attacker craft a path into the process network that looks like a legitimate, provisioned endpoint.

From a compliance standpoint, an ISE instance supporting electronic access control to a BES Cyber System is a candidate Electronic Access Control or Monitoring System under NERC CIP, which drags it into CIP-005 and CIP-007 obligations for access management and patch evaluation. Under IEC 62443, this is a conduit and zone-boundary control whose compromise weakens the segmentation assumptions the whole architecture rests on. Pipeline operators under TSA SD-02C and water utilities under AWIA 2018 should likewise account for access-control infrastructure in their identification of critical cyber systems, since a boundary authenticator failing open to information disclosure undercuts the segmentation those mandates expect.

Compensating Controls

Do not rely on a future patch as your only response, and do not run active scans against a production ISE node without a maintenance window. Aggressive probing of the provisioning service can disrupt endpoint onboarding and, in constrained OT networks, cascade into access failures for field devices that depend on timely posture checks.

BreachSpider Intel

BreachSpider tracks exploitation signals and patch availability for CVE-2026-76433 and other boundary access-control exposures affecting OT environments. Monitor the advisory and KEV program status through BreachSpider.