CVE-2026-76488

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit could allow the attacker to access sensitive files from the underlying file system of an affected device, including key materials that could be used to elevate privileges to root on the affected APIC and on managed switches.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-264

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-07: 210-07
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew

    CVE-2026-76488 A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to acc… https://www.cve.org/CVERecord?id=CVE-2026-76488

    00000918
    58.1K followersView on X
  • VulniPulse@vulnipulse

    CVE advisory (MEDIUM): CVE-2026-76488 - cisco: Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability. https://vulnipulse.com/advisories/cisco-cisco-sa-apic-info-priv-enadb5vd #CVE #CyberSecurity #Cisco #CiscoAPIC

    0000031
    7 followersView on X

Explore more