Junglewise Threat Intelligence

CVE-2026-20136: Cisco ISE command injection in CLI

CVE-2026-20136 · Severity: medium · CVSS 6 · Published 2026-04-15

Technologies: Cisco ISE Passive Identity Connector, Cisco Identity Services Engine. Vendors: Cisco.

Executive brief

Cisco Identity Services Engine (ISE), a platform used to manage secure network access, contains a security flaw in its command-line interface. An authorized administrator with local access could exploit this flaw to gain full control (root access) over the underlying operating system. While this requires existing administrative credentials, a successful attack could allow a user to bypass intended security restrictions and compromise the integrity of the identity management system.

Technical details

A command injection vulnerability exists in the Command Line Interface (CLI) of Cisco ISE and ISE-PIC due to improper encoding or escaping of output (CWE-116) and insufficient validation of user-supplied input. An attacker with local access and high administrative privileges (PR:H) can exploit this by providing crafted input to specific CLI commands. Successful exploitation allows the execution of arbitrary commands on the underlying Linux operating system with root-level privileges. Cisco has released fixed software versions (3.3 Patch 11, 3.4 Patch 6, and 3.5 Patch 3) to address this issue; no workarounds are available.

Affected products

  • Cisco Identity Services Engine (ISE) 3.3 and earlier, 3.4, 3.5
  • Cisco ISE Passive Identity Connector (ISE-PIC) 3.3 and earlier, 3.4, 3.5

Timeline

  • 2026-04-15: advisory: Initial public release of Cisco advisory cisco-sa-ise-cmd-inj-5WSJcYJB
  • 2026-04-15: patched: Fixed releases 3.3 Patch 11, 3.4 Patch 6, and 3.5 Patch 3 made available.

References

Related threats