Junglewise Threat Intelligence

CVE-2026-20146: Cisco ISE path traversal in management interface

CVE-2026-20146 · Severity: medium · CVSS 5.5 · Published 2026-07-15

Executive brief

Cisco Identity Services Engine (ISE), a platform used to manage secure network access, contains a vulnerability that could allow an authorized administrator to access or delete restricted system files. By sending a specially crafted request to the management interface, an attacker with administrative credentials could bypass security restrictions to view sensitive data or disrupt operations by deleting critical files. While this requires existing administrative access, it represents a significant risk to data confidentiality and system integrity.

Technical details

A path traversal vulnerability (CWE-22) exists in the web-based management interface of Cisco ISE and ISE-PIC due to improper validation of user-supplied input. An attacker with high-privileged administrative credentials can exploit this by sending crafted HTTP requests containing directory traversal sequences (e.g., ../) to the affected system. Successful exploitation allows the attacker to bypass directory restrictions to read sensitive configuration files or delete arbitrary files on the underlying Linux-based operating system. The vulnerability affects multiple versions including 3.1, 3.2, 3.3, 3.4, and 3.5. Cisco has announced fixed releases (e.g., 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) scheduled for September 2026.

Affected products

  • Cisco Identity Services Engine (ISE) 3.1.0 through 3.5 Patch 3
  • Cisco ISE Passive Identity Connector (ISE-PIC) 3.1.0 through 3.4 Patch 5

Timeline

  • 2026-07-15: advisory: Initial public release by Cisco
  • 2026-07-15: disclosed
  • 2026-09-01: patched: Estimated availability of fixed software patches

References

Related threats