Executive brief
Cisco Identity Services Engine (ISE) is used to manage network access and security policies across enterprise networks. A vulnerability in the IPsec Open API endpoint allows authenticated administrators with valid credentials to inject arbitrary operating system commands, potentially leading to complete system compromise and unauthorized root access. The vulnerability requires specific network configuration but poses a critical risk to affected deployments.
Technical details
This is a command injection vulnerability (CWE-78) in the IPsec Open API endpoint of Cisco ISE, caused by insufficient input validation on user-supplied parameters in API calls. The vulnerability requires an authenticated attacker with valid administrative credentials; additionally, the affected device must have more than one network interface with at least one configured as an active IPsec tunnel between ISE and a Network Access Device (NAD). A successful exploit allows arbitrary command execution on the underlying operating system. Cisco has released software patches, and the advisory notes that privilege escalation to root is easily achievable from the compromised privilege level, warranting a High SIR designation despite the medium CVSS score.
Affected products
- Cisco Identity Services Engine
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched