Executive brief
Cisco Identity Services Engine (ISE) is a network access control platform used to manage authentication and authorization for enterprise networks. A critical vulnerability allows authenticated administrators to execute arbitrary operating system commands through insufficient input validation, potentially giving attackers complete system control and causing network-wide authentication outages.
Technical details
CVE-2026-20176 is a command injection vulnerability in Cisco ISE due to insufficient validation of user-supplied input in HTTP requests. An authenticated attacker with high-privileged administrative credentials can send a crafted HTTP request to execute arbitrary commands at the operating system level, including privilege escalation to root. The attack requires network accessibility to the ISE device and valid high-privileged admin credentials. Successful exploitation grants system-level access; in single-node deployments, it can trigger denial of service affecting all unauthenticated endpoints. Cisco has released software updates; no workarounds are available.
Affected products
- Cisco Identity Services Engine
Timeline
- 2026-09-16: disclosed