GPU VulnDB

Database/Control plane, storage & DevOps

Cisco ISE: unauthenticated API endpoint allows full authentication bypass on the appliance

CVSS 10.0CVE-2026-76460Control plane, storage & DevOpsKnown exploitedcurated

Impact

An unauthenticated attacker who can reach the ISE API gets administrative access to the appliance, bypassing the web management interface entirely. ISE is typically the TACACS+/RADIUS authority for switches, BMC jump paths and management-VLAN admission in a datacenter, so control of it means control of who may log into fabric and out-of-band devices, and the ability to mint or relax access policy for the whole fleet. CISA lists this as known-exploited, so exposure is not theoretical. CVSS is 10.0 with scope change: the compromise does not stop at the appliance.

Who can reach it

Anyone with network reach to the ISE API - no authentication and no user interaction required. In most deployments that is the management network, but ISE is often reachable more widely than operators assume.

What to do

Apply the Cisco fixed release named in advisory cisco-sa-ISE-ABP-VNSW7Tn5 for your 3.1/3.2/3.3 train; ISE upgrades require an appliance reboot and a maintenance window per node, and in a distributed deployment the nodes must be patched in Cisco's documented order. Until patched, restrict API reachability to a small admin range. Because this is in KEV, treat it as already exploited: review admin accounts, policy changes and logs after patching.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.