Security Advisory Desk
mediumQCS priority 82/100Cisco

Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability

A security flaw in Cisco's Application Policy Infrastructure Controller (APIC) allows someone with administrative login details to improperly access sensitive files on the device. This happens because the system does not correctly restrict access to its file system. By entering specially crafted values in certain fields, an attacker can view important files, including keys that could give them full control over the device and connected switches. Cisco has issued updated software to fix this issue, but there are no temporary fixes or workarounds available.

QCS published 9/10/2026, 1:42:38 am ISTVendor disclosure 7/10/2026, 9:30:00 pm ISTVerified 9/10/2026, 1:42:38 am ISTRevision 1

In plain language

What this advisory means

A security flaw in Cisco's Application Policy Infrastructure Controller (APIC) allows someone with administrative login details to improperly access sensitive files on the device. This happens because the system does not correctly restrict access to its file system. By entering specially crafted values in certain fields, an attacker can view important files, including keys that could give them full control over the device and connected switches. Cisco has issued updated software to fix this issue, but there are no temporary fixes or workarounds available.

Technical explanation

How the issue affects the environment

The vulnerability lies within the export policies feature of Cisco APIC, where insufficient file system access control permits an authenticated remote attacker with valid administrative credentials to submit crafted inputs via UI fields, leading to unauthorized disclosure of sensitive filesystem files. These files include key materials that could enable privilege escalation to root on the APIC and managed switches. The issue is tracked as CVE-2026-76488 (CWE-264), with a CVSS 3.1 base score of 6.5 (medium severity). Cisco released fixed software starting with versions 6.0(9h) and 6.1(3f); earlier versions are vulnerable. There are no viable workarounds.

Operational impact

Why teams should care

If exploited, an attacker with admin credentials can access sensitive files including cryptographic keys, potentially escalating privileges to root level. This can compromise the integrity and security of the APIC device and its managed network switches, possibly leading to unauthorized network control or data breaches. No workarounds mean organizations must promptly apply the fixed software to mitigate risk, impacting maintenance and upgrade planning.

Immediate action

Upgrade Cisco APIC software to a fixed release version—6.0(9h), 6.1(3f), or later—to fully address the vulnerability. Verify the upgrade completion and monitor for any access anomalies. Since no workarounds exist, prioritizing the upgrade is critical.

Affected and fixed releases

Affected versionsCisco APIC releases 5.3 and earlier
Fixed versions6.0(9h), 6.1(3f)

Temporary risk reduction

Cisco states there are no workarounds that address this vulnerability. Temporary measures are ineffective; upgrading the software is the recommended remediation.

Evidence and validation checklist

  • Cisco PSIRT Advisory cisco-sa-apic-info-priv-enAdB5vD dated 2026-10-07
  • CVE-2026-76488 assigned and described
  • Details of vulnerability mechanism and impact
  • Fixed software versions and no workarounds stated
  • No known exploitation or public announcements reported

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source