Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
4.9
CVE-2026-76431
Cisco · Cisco Identity Services Engine Software

Cisco Identity Services Engine Arbitrary File Deletion Vulnerability

Description

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of directory traversal character sequences in a user-supplied file path before the request is validated. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to delete arbitrary files and directories on the underlying operating system of the affected device.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p72, 3.1.0 p11, 3.2.0, 3.1.0, 3.3.0, 3.4.0, 3.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco ise passive identity connectormitre_affected90%
cisidentity services engine (ise)cert_advisory90%
ciscisco secure firewall management centercert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn

Related News (3 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco ISE und ISE-PIC: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco Secure Firewall Management Center: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-76431 | Cisco Identity Services Engine Software File Management path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.14.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-22
PublishedSep 16, 2026
Last enriched11d ago
Trending Score10
Source articles3
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 13
MEDIUMCVE-2026-20121
CIsco FTD Bypass Access List
Trending: 13
MEDIUMCVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Trending: 11
MEDIUMCVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Trending: 11
HIGHCVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026