Junglewise Threat Intelligence

CVE-2026-20186: Cisco Identity Services Engine command injection and privilege escalation

CVE-2026-20186 · Severity: critical · CVSS 9.9 · Published 2026-04-15

Technologies: Cisco Identity Services Engine. Vendors: Cisco.

Executive brief

Cisco Identity Services Engine (ISE) is a security policy management platform that controls access to corporate networks. A vulnerability in this system allows an attacker with basic administrative credentials to take full control of the underlying operating system. This could lead to the theft of sensitive network data, unauthorized access for new devices, or a complete shutdown of network authentication services.

Technical details

A command injection vulnerability (CWE-77) exists in Cisco Identity Services Engine (ISE) due to insufficient validation of user-supplied input in HTTP requests. An authenticated remote attacker with at least 'Read Only Admin' privileges can exploit this by sending crafted HTTP requests to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying Linux operating system, initially with user-level access, and subsequently elevate those privileges to root. In single-node deployments, this can also lead to a Denial of Service (DoS) condition where new endpoints cannot authenticate to the network. Cisco has released patches to address this issue in versions 3.2, 3.3, and 3.4.

Affected products

  • Cisco Identity Services Engine (ISE) 3.2 before 3.2 Patch 8, 3.3 before 3.3 Patch 8, 3.4 before 3.4 Patch 4

Timeline

  • 2026-04-15: advisory: Initial public release by Cisco
  • 2026-04-15: disclosed

References

Related threats