Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-76460

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 58.5%
CVSS Severity
CVSS v3 Score 10.0
Proposed Action
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Ransomware Campaign
Unknown
Products affected by CVE-2026-76460


Contact Us

Shodan ® - All rights reserved