Junglewise Threat Intelligence

CVE-2026-20148: Cisco ISE path traversal in underlying operating system

CVE-2026-20148 · Severity: medium · CVSS 4.9 · Published 2026-04-15

Technologies: Cisco ISE Passive Identity Connector, Cisco Identity Services Engine. Vendors: Cisco.

Executive brief

Cisco Identity Services Engine (ISE) is a security policy management platform used to control network access and provide visibility into users and devices. A vulnerability in this system could allow an authorized administrator to bypass security restrictions and read sensitive system files. This could lead to the exposure of confidential configuration data or system credentials, potentially compromising the overall security of the network infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in Cisco ISE and Cisco ISE-PIC due to improper validation of user-supplied input in HTTP requests. An authenticated, remote attacker with valid administrative credentials can exploit this by sending a crafted HTTP request to the affected system. Successful exploitation allows the attacker to traverse the file system and read arbitrary files on the underlying operating system. This vulnerability is tracked by Cisco Bug ID CSCws52717. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Identity Services Engine (ISE) < 3.1 Patch 11, 3.2 < Patch 10, 3.3 < Patch 11, 3.4 < Patch 6, 3.5 < Patch 3
  • Cisco ISE Passive Identity Connector (ISE-PIC) < 3.1 Patch 11, 3.2 < Patch 10, 3.3 < Patch 11, 3.4 < Patch 6

Timeline

  • 2026-04-15: advisory: Initial public release by Cisco
  • 2026-04-28: patched: Updated fixed release availability information

References

Related threats