Executive brief
Cisco Identity Services Engine (ISE) is a security policy management platform that controls network access. A vulnerability in this system allows an attacker with basic administrative credentials to take full control of the underlying operating system. This could lead to the theft of sensitive data, unauthorized network access for rogue devices, or a complete shutdown of the authentication service, preventing legitimate users from connecting to the network.
Technical details
A vulnerability in Cisco Identity Services Engine (ISE) is caused by insufficient validation of user-supplied input in HTTP requests. An authenticated, remote attacker with at least Read Only Admin credentials can exploit this by sending a crafted HTTP request to the affected device. Successful exploitation allows for arbitrary command execution on the underlying operating system, starting with user-level access and potentially escalating to root privileges. In single-node deployments, this can lead to a Denial of Service (DoS) where new endpoints cannot authenticate. The vulnerability is associated with CWE-22 (Path Traversal) and CWE-77 (Command Injection). Cisco has released software updates to address this issue.
Affected products
- Cisco Identity Services Engine Earlier than 3.2; 3.2 before Patch 8; 3.3 before Patch 8; 3.4 before Patch 4
Timeline
- 2026-04-15: disclosed
- 2026-04-15: advisory
- 2026-04-15: patched