Junglewise Threat Intelligence

CVE-2026-20176: Cisco ISE remote code execution via command injection

CVE-2026-20176 · Severity: critical · CVSS 9.1 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is a network access control platform used to manage authentication and authorization for enterprise networks. A critical vulnerability allows authenticated administrators to execute arbitrary operating system commands through insufficient input validation, potentially giving attackers complete system control and causing network-wide authentication outages.

Technical details

CVE-2026-20176 is a command injection vulnerability in Cisco ISE due to insufficient validation of user-supplied input in HTTP requests. An authenticated attacker with high-privileged administrative credentials can send a crafted HTTP request to execute arbitrary commands at the operating system level, including privilege escalation to root. The attack requires network accessibility to the ISE device and valid high-privileged admin credentials. Successful exploitation grants system-level access; in single-node deployments, it can trigger denial of service affecting all unauthenticated endpoints. Cisco has released software updates; no workarounds are available.

Affected products

  • Cisco Identity Services Engine

Timeline

  • 2026-09-16: disclosed

References

Related threats