Database/Control plane, storage & DevOps
Cisco ISE: unauthenticated API endpoint allows full authentication bypass on the appliance
Impact
An unauthenticated attacker who can reach the ISE API gets administrative access to the appliance, bypassing the web management interface entirely. ISE is typically the TACACS+/RADIUS authority for switches, BMC jump paths and management-VLAN admission in a datacenter, so control of it means control of who may log into fabric and out-of-band devices, and the ability to mint or relax access policy for the whole fleet. CISA lists this as known-exploited, so exposure is not theoretical. CVSS is 10.0 with scope change: the compromise does not stop at the appliance.
Who can reach it
Anyone with network reach to the ISE API - no authentication and no user interaction required. In most deployments that is the management network, but ISE is often reachable more widely than operators assume.
What to do
Apply the Cisco fixed release named in advisory cisco-sa-ISE-ABP-VNSW7Tn5 for your 3.1/3.2/3.3 train; ISE upgrades require an appliance reboot and a maintenance window per node, and in a distributed deployment the nodes must be patched in Cisco's documented order. Until patched, restrict API reachability to a small admin range. Because this is in KEV, treat it as already exploited: review admin accounts, policy changes and logs after patching.
References
Related entries
- SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interfaceCVE-2026-83548 · SonicWall SMA1000 appliance (Work Place interface, alternate access path)Critical
- GitLab: unauthenticated arbitrary file read via the repository commits APICVE-2026-85706 · GitLab CE/EE (repository commits API)Critical
- Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts): The pipelines frontend hands any unauthenticatedNCVD-2026-042-kubeflow-pipelines-frontend-prox · Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts)Critical
- HTCondor (condor_credd): condor_credd can be told to create or write files as root outsideCVE-2021-25311 · HTCondor (condor_credd)Critical
- RKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCVE-2023-32191 · RKE / Rancher (k8s control plane)Critical
- VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows theyCVE-2023-34063 · VMware Aria Automation (missing access control)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.