---
id: CVE-2026-76460
title: "A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.\r\n\r\nThis vulnerability is due to insufficient authentication control on an API endpoint"
summary: "A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.\r\n\r\nThis vulnerability is due to insufficient authentication control on an API endpoint. An attack…"
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-648
vendor: cisco
product: identity_services_engine
affected:
  - identity_services_engine = 3.1.0
  - identity_services_engine = 3.2.0
  - identity_services_engine = 3.3.0
  - identity_services_engine = 3.4.0
  - identity_services_engine = 3.5.0
  - identity_services_engine_passive_identity_connector = 3.1.0
  - identity_services_engine_passive_identity_connector = 3.2.0
  - identity_services_engine_passive_identity_connector = 3.3.0
  - identity_services_engine_passive_identity_connector = 3.4.0
  - identity_services_engine_passive_identity_connector = 3.5.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:46:31.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76460'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
    label: psirt@cisco.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - kev
  - in-the-wild
  - cve.org
  - exploit-available
  - csaf
  - vendor-advisory
  - cisco
kev: true
kevDateAdded: '2026-09-16'
kevDueDate: '2026-09-19'
kevRansomware: false
exploited: true
zeroDay: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-16T20:40:04.724814Z'
ingestedAt: '2026-09-16T16:37:52.193Z'
epss: 0.00784
epssPercentile: 0.54107
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/S3v3n-JG/CVE-2026-76460'
  checkedAt: '2026-09-21T15:30:40.767Z'
---

## Overview

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.

This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

## Affected

- `identity_services_engine = 3.1.0`
- `identity_services_engine = 3.2.0`
- `identity_services_engine = 3.3.0`
- `identity_services_engine = 3.4.0`
- `identity_services_engine = 3.5.0`
- `identity_services_engine_passive_identity_connector = 3.1.0`
- `identity_services_engine_passive_identity_connector = 3.2.0`
- `identity_services_engine_passive_identity_connector = 3.3.0`
- `identity_services_engine_passive_identity_connector = 3.4.0`
- `identity_services_engine_passive_identity_connector = 3.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ISE-ABP-VNSW7Tn5** · Cisco · affected: Cisco ISE Passive Identity Connector 3.4.0, Cisco Identity Services Engine Software (30 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5)
