Executive brief
Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which are identity and access management platforms used for network authentication and device compliance, contain improper input validation vulnerabilities. An attacker on the network could exploit these flaws without authentication to compromise the confidentiality, integrity, and availability of the identity management system, potentially allowing unauthorized access to protected networks and customer data.
Technical details
The vulnerabilities are grouped under CWE-20 (Improper Input Validation) and related classes including CWE-74, CWE-284, CWE-522, CWE-669, and CWE-269. These issues were identified through Cisco's internal security review of the ISE and ISE-PIC engineering codebase. The vulnerabilities are network-reachable and require no authentication or user interaction to exploit (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C). At least one vulnerability in the CWE-284 (improper access control) category is known to be actively exploited in the wild. Cisco has released patched versions across all supported release branches (3.1 through 3.5), with patches identified in the Fixed Software section.
Affected products
- Cisco Identity Services Engine 3.0 and earlier, 3.1 before 3.1 Patch 12, 3.2 before 3.2 Patch 11, 3.3 before 3.3 Patch 12, 3.4 before 3.4 Patch 7, 3.5 before 3.5 Patch 4
- Cisco ISE Passive Identity Connector 3.4 and earlier
Timeline
- 2026-09-16: disclosed: CVE-2026-20237 published as part of Cisco hardening release advisory
- exploited: At least one vulnerability (CWE-284 improper access control) known to be actively exploited