Executive brief
Cisco Identity Services Engine (ISE) is a network security platform that manages authentication and access control across enterprise networks. A flaw in its web-based administrative interface allows authenticated administrators to bypass permission checks and modify system configuration that should be restricted. An attacker with valid admin credentials could exploit this to alter system settings beyond their authorization level.
Technical details
This vulnerability stems from insufficient server-side validation of Administrator permissions in the ISE web management interface (CWE-285: Improper Authorization). An authenticated attacker with valid Administrator credentials can submit a crafted HTTP request to bypass permission checks and modify configuration elements (such as file descriptions) that should be restricted to higher-privilege roles. The attack requires valid administrative credentials and network access to the management interface, but no user interaction. The vulnerability affects ISE releases 3.2 and earlier; fixes are available in ISE 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, with ISE-PIC 3.4 being the final supported release.
Affected products
- Cisco Identity Services Engine 3.2 and earlier
- Cisco ISE Passive Identity Connector 3.4 and earlier
Timeline
- 2026-09-16: disclosed
- 2026-09-16: advisory