Junglewise Threat Intelligence

CVE-2026-20285: Cisco Identity Services Engine authorization bypass in web management interface

CVE-2026-20285 · Severity: medium · CVSS 4.3 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is a network security platform that manages authentication and access control across enterprise networks. A flaw in its web-based administrative interface allows authenticated administrators to bypass permission checks and modify system configuration that should be restricted. An attacker with valid admin credentials could exploit this to alter system settings beyond their authorization level.

Technical details

This vulnerability stems from insufficient server-side validation of Administrator permissions in the ISE web management interface (CWE-285: Improper Authorization). An authenticated attacker with valid Administrator credentials can submit a crafted HTTP request to bypass permission checks and modify configuration elements (such as file descriptions) that should be restricted to higher-privilege roles. The attack requires valid administrative credentials and network access to the management interface, but no user interaction. The vulnerability affects ISE releases 3.2 and earlier; fixes are available in ISE 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, with ISE-PIC 3.4 being the final supported release.

Affected products

  • Cisco Identity Services Engine 3.2 and earlier
  • Cisco ISE Passive Identity Connector 3.4 and earlier

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: advisory

References

Related threats