A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive…

cve CVE-2026-76444 1 source, 1 claim · Watch

NVD writes:
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device. the claim
Severity
MEDIUM NVD
CVSS
5.3 NVD
Vendor
Cisco NVD
Product
Cisco Identity Services Engine Software NVD
CWE
CWE-306 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-09-16first spoke of it: A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.NVD

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.

What it is to other things

affectscisco/identity_services_engine
NVD
affectscisco/identity_services_engine_passive_identity_connector
NVD
made_bycisco
NVD

In words only, so not counted until a person confirms one:

affectscisco/cisco_identity_services_engine_software
NVD says “Cisco · Cisco Identity Services Engine Software”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCyes
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:39 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-306
receipt
Source
NVD
Its words
CWE-306
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-306
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDCisco Identity Services Engine Software
receipt
Source
NVD
Its words
Cisco Identity Services Engine Software
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco Identity Services Engine Software
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCMEDIUM
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:39 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDCisco
receipt
Source
NVD
Its words
Cisco
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 6"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.\r\n\r\nThis vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device."
      }
    ],
    "id": "CVE-2026-76444",
    "lastModified": "2026-09-28T13:06:58.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-76444",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-19T13:46:10.724095Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-16T21:17:19.463",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-306"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.
zetlyn/cve-nvd · 2026-09-16
automatable yes cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cwe CWE-306 exploitation none product Cisco Identity Services Engine Software severity MEDIUM status Analyzed technical_impact partial vendor Cisco source