Executive brief
Cisco Identity Services Engine (ISE), a platform used to manage secure network access for users and devices, contains a vulnerability that could allow an attacker to take full control of the system. An attacker with valid administrative credentials can execute malicious commands to gain root-level access, potentially stealing sensitive data or causing a total network outage. In certain setups, this could prevent all new users and devices from connecting to the corporate network until the system is restored.
Technical details
A command injection vulnerability (CWE-77) exists in Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input in HTTP requests. An authenticated, remote attacker with valid administrative credentials can exploit this by sending a crafted HTTP request to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with user-level privileges and subsequently elevate those privileges to root. In single-node deployments, this can lead to a denial of service (DoS) where new endpoints are unable to authenticate to the network. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine (ISE) 3.1 before Patch 11, 3.2 before Patch 10, 3.3 before Patch 11, 3.4 before Patch 6, 3.5 before Patch 3
- Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) 3.1 before Patch 11, 3.2 before Patch 10, 3.3 before Patch 11, 3.4 before Patch 6
Timeline
- 2026-04-15: advisory: Initial public release by Cisco
- 2026-04-28: patched: Updated fixed release availability information