Description
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device.

This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A vulnerability in an internal service of Cisco Identity Services Engine (ISE) and its passive connector component allows an unauthenticated remote attacker to retrieve sensitive configuration information. The flaw stems from missing authentication on the Policy Runtime Repository Table (PRRT) service, permitting a crafted request to expose internal settings. The primary consequence is disclosure of confidential configuration data, which could provide attackers with insight into network policies, user roles, and device credentials.

Affected Systems

Affected products include Cisco Identity Services Engine software and Cisco ISE Passive Identity Connector. The CVE does not list specific affected versions, so any deployment of these products prior to an eventual vendor patch may be vulnerable.

Risk and Exploitability

The flaw received a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1%, reflecting a low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires remote, unauthenticated access to the device's internal PRRT service. Once the attacker sends a crafted request, the service will return configuration details. While the probability of exploitation is low, the disclosure of configuration data could aid further attacks or information gathering.

Generated by OpenCVE AI on September 18, 2026 at 01:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco ISE or ISE‑PIC patch or upgrade to a version that addresses the missing authentication flaw.
  • Configure network segmentation or firewall rules to block unauthenticated access to the PRRT service, ensuring only trusted hosts can communicate with the ISE device.
  • If the PRRT service is not required for your environment, disable it or restrict its availability to a dedicated, secure subnet.

Generated by OpenCVE AI on September 18, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco identity Services Engine
CPEs cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*
Vendors & Products Cisco identity Services Engine

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device.
Title Cisco Identity Services Engine Information Disclosure Vulnerability
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Cisco Identity Services Engine Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-19T14:21:55.295Z

Reserved: 2026-08-19T12:02:03.635Z

Link: CVE-2026-76444

cve-icon Vulnrichment

Updated: 2026-09-19T14:18:17.227Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T21:17:19.463

Modified: 2026-09-28T13:06:58.163

Link: CVE-2026-76444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function