« Back to list

CVE-2026-76433

Status: AnalyzedMedium (5.3)—

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device.

This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the software processes provisioning resource requests. An attacker could exploit this vulnerability by sending a crafted request to the provisioning download service. A successful exploit could allow the attacker to access protected files without authentication, potentially exposing sensitive information.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-76433",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-76433",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-17T14:07:58.643636Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Cisco",
          "product": "Cisco Identity Services Engine Software",
          "versions": [
            {
              "status": "affected",
              "version": "3.1.0"
            },
            {
              "status": "affected",
              "version": "3.1.0 p1"
            },
            {
              "status": "affected",
              "version": "3.1.0 p3"
            },
            {
              "status": "affected",
              "version": "3.1.0 p2"
            },
            {
              "status": "affected",
              "version": "3.2.0"
            },
            {
              "status": "affected",
              "version": "3.1.0 p4"
            },
            {
              "status": "affected",
              "version": "3.1.0 p5"
            },
            {
              "status": "affected",
              "version": "3.2.0 p1"
            },
            {
              "status": "affected",
              "version": "3.1.0 p6"
            },
            {
              "status": "affected",
              "version": "3.2.0 p2"
            },
            {
              "status": "affected",
              "version": "3.1.0 p7"
            },
            {
              "status": "affected",
              "version": "3.3.0"
            },
            {
              "status": "affected",
              "version": "3.2.0 p3"
            },
            {
              "status": "affected",
              "version": "3.2.0 p4"
            },
            {
              "status": "affected",
              "version": "3.1.0 p8"
            },
            {
              "status": "affected",
              "version": "3.2.0 p5"
            },
            {
              "status": "affected",
              "version": "3.2.0 p6"
            },
            {
              "status": "affected",
              "version": "3.1.0 p9"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 2"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 1"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 3"
            },
            {
              "status": "affected",
              "version": "3.4.0"
            },
            {
              "status": "affected",
              "version": "3.2.0 p7"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 4"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 1"
            },
            {
              "status": "affected",
              "version": "3.1.0 p10"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 5"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 6"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 2"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 7"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 3"
            },
            {
              "status": "affected",
              "version": "3.5.0"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 4"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 8"
            },
            {
              "status": "affected",
              "version": "3.2 Patch 8"
            },
            {
              "status": "affected",
              "version": "3.5 Patch 1"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 9"
            },
            {
              "status": "affected",
              "version": "3.2 Patch 9"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 5"
            },
            {
              "status": "affected",
              "version": "3.5 Patch 3"
            },
            {
              "status": "affected",
              "version": "3.5 Patch 2"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 10"
            },
            {
              "status": "affected",
              "version": "3.3 Patch 11"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 6"
            },
            {
              "status": "affected",
              "version": "3.2 Patch 10"
            },
            {
              "status": "affected",
              "version": "3.1.0 p72"
            },
            {
              "status": "affected",
              "version": "3.1.0 p11"
            },
            {
              "status": "affected",
              "version": "3.4 Patch 7"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Cisco",
          "product": "Cisco ISE Passive Identity Connector",
          "versions": [
            {
              "status": "affected",
              "version": "3.2.0"
            },
            {
              "status": "affected",
              "version": "3.1.0"
            },
            {
              "status": "affected",
              "version": "3.3.0"
            },
            {
              "status": "affected",
              "version": "3.4.0"
            },
            {
              "status": "affected",
              "version": "3.5.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-09-16T21:17:15.017",
  "references": [
    {
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the software processes provisioning resource requests. An attacker could exploit this vulnerability by sending a crafted request to the provisioning download service. A successful exploit could allow the attacker to access protected files without authentication, potentially exposing sensitive information."
    }
  ],
  "lastModified": "2026-09-28T13:16:49.303",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAD3927B-E71E-4497-8928-11FFA9965479",
              "versionEndExcluding": "3.3.0",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B92D6093-92D7-4A0A-8954-DB99BC05E90D",
              "versionEndExcluding": "3.3.0",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}