---
cve: "CVE-2026-76444"
severity: "MEDIUM"
cvss: 5.3
epss: "0.3%"
vendor: "Cisco"
kev: false
exploited: false
published: "2026-09-16 21:17:19"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T17:01:55+02:00"
---

# CVE-2026-76444

> 5.3 MEDIUM

## Beschreibung

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.

This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## BSI-Hinweise (deutsch)

- [Cisco ISE und ISE-PIC: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3425) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Cisco Identity Services Engine (ISE) und ISE-PIC ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, Sicherheitsmaßnahmen zu umgehen, Berechtigungen zu erweitern, SQL-Injection-Angriffe durchzuführen, Sitzungen zu übernehmen, sensible Informationen oder Anmeldedaten offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen und Cross-Site-Scripting-Angriffe durchzuführen.

## Referenzen

- <https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-76444) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
