Back

CRITICAL KEV

Cisco Identity Services Engine Authentication Bypass Vulnerability

Published Sep 16, 2026 ·Due Sep 19, 2026

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Analyzed
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a