Junglewise Threat Intelligence

CVE-2026-20181: Cisco ISE and ISE-PIC command injection in underlying OS

CVE-2026-20181 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Executive brief

Cisco Identity Services Engine (ISE) is a security policy management platform that controls access to corporate networks. A vulnerability in this system could allow an administrator to bypass security restrictions and take full control of the underlying server. This could lead to a total service outage, preventing new users or devices from connecting to the network, and potentially allowing an attacker to access sensitive internal data.

Technical details

A vulnerability in Cisco ISE and ISE-PIC (CVE-2026-20181) stems from insufficient validation of user-supplied input in HTTP requests, specifically related to path traversal (CWE-22). An authenticated, remote attacker with valid administrative credentials can exploit this by sending a crafted HTTP request to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system, initially with user-level access and subsequently escalating to root privileges. In single-node deployments, this can lead to a complete Denial of Service (DoS) for network authentication services. Cisco has released software updates to address this issue; no workarounds are available.

Affected products

  • Cisco Identity Services Engine (ISE) 3.1, 3.2, 3.3 (prior to Patch 11), 3.4 (prior to Patch 6), 3.5 (prior to Patch 4)
  • Cisco ISE Passive Identity Connector (ISE-PIC) 3.1, 3.2, 3.3, 3.4

Timeline

  • 2026-06-17: advisory: Initial public release by Cisco
  • 2026-06-19: other: Advisory updated to clarify hot patch availability

References

Related threats