5.3
CVE-2026-76439
- EPSS 0.32%
- Veröffentlicht 16.09.2026 20:17:47
- Zuletzt bearbeitet 28.09.2026 13:12:38
- Erkennungen
Cisco Identity Services Engine Event Injection Vulnerability
A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal interface that is exposed through the guest portal. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to manipulate the posture status on the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version < 3.3.0
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch10
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch11
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch8
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch9
Cisco ≫ Identity Services Engine Version 3.4.0 Update -
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.5.0 Update -
Cisco ≫ Identity Services Engine Version 3.5.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.5.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.5.0 Update patch3
Cisco ≫ Identity Services Engine Passive Identity Connector Version < 3.3.0
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch1
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch10
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch11
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch2
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch3
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch4
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch5
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch6
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch7
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch8
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.3.0 Update patch9
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update -
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch1
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch2
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch3
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch4
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch5
Cisco ≫ Identity Services Engine Passive Identity Connector Version 3.4.0 Update patch6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.257 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cisco PSIRT | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4