CVE-2026-76444 PUBLISHED

Cisco Identity Services Engine Information Disclosure Vulnerability

Assigner: cisco
Reserved: 19.08.2026 Published: 16.09.2026 Updated: 16.09.2026

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.

This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Cisco
Product Cisco Identity Services Engine Software
Versions Default: unknown
  • Version 3.4.0 is affected
  • Version 3.4 Patch 1 is affected
  • Version 3.4 Patch 2 is affected
  • Version 3.4 Patch 3 is affected
  • Version 3.5.0 is affected
  • Version 3.4 Patch 4 is affected
  • Version 3.5 Patch 1 is affected
  • Version 3.4 Patch 5 is affected
  • Version 3.5 Patch 3 is affected
  • Version 3.5 Patch 2 is affected
  • Version 3.4 Patch 6 is affected
Vendor Cisco
Product Cisco ISE Passive Identity Connector
Versions Default: unknown
  • Version 3.4.0 is affected
  • Version 3.5.0 is affected

Exploits

The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory.

The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.

References

Problem Types

  • Missing Authentication for Critical Function cwe