Executive brief
Cisco Identity Services Engine (ISE) is a network access control and identity management platform used to protect enterprise networks. A weakness in its web-based management interface allows an authenticated attacker with Administrator credentials to modify configuration settings beyond their intended permissions. The practical impact is limited to configuration tampering by insiders who already have administrative access, but could enable privilege abuse or lateral movement within the system.
Technical details
This is an authorization bypass vulnerability caused by insufficient server-side validation of Administrator permissions in the web management interface of Cisco ISE. The attacker must already possess valid Administrator credentials and can exploit it by crafting and submitting a malicious HTTP request to modify configuration file descriptions on specific management pages. CVE-2026-20286 affects Cisco ISE regardless of device configuration, while a related CVE-2026-20285 also affects Cisco ISE-PIC. Cisco has confirmed that CVE-2026-20286 does not affect ISE-PIC. Patches are available: ISE 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4, and later releases include fixes.
Affected products
- Cisco Identity Services Engine 3.2 and earlier; 3.3 before Patch 12; 3.4 before Patch 7; 3.5 before Patch 4
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Patches released for ISE 3.3, 3.4, and 3.5