Executive brief
Cisco Identity Services Engine (ISE) is used to manage network access and authentication for enterprise devices. A flaw in the bring-your-own-device onboarding workflow allows an attacker to hijack another user's session and gain unauthorized access to protected corporate networks, bypassing security controls that are supposed to enforce 802.1X network authentication.
Technical details
This vulnerability (CVE-2026-20071) is caused by insufficient authentication checks in the SSID BYOD onboarding workflow of Cisco ISE. An unauthenticated, adjacent attacker can spoof a legitimate user and trigger a redirection to the guest web portal, thereby hijacking the victim's onboarding session. The attack requires adjacent network proximity and user interaction (UI:R). A successful exploit grants the attacker access to protected 802.1X networks that the hijacked user would have been granted. Cisco has released patch versions for affected ISE releases (3.2 Patch 8 and later); no workarounds are available and the vulnerability has not yet been exploited in the wild.
Affected products
- Cisco Identity Services Engine 3.1 and earlier; 3.2, 3.3 prior to 3.3 Patch 12; 3.4 prior to 3.4 Patch 7; 3.5 prior to 3.5 Patch 4
Timeline
- 2026-09-16: disclosed