Executive brief
Cisco Identity Services Engine (ISE) and ISE-PIC are network access control systems that manage user authentication and authorization for enterprise networks. An authenticated administrator with valid credentials could inject malicious commands through the web management interface, gaining root-level access and executing arbitrary code. This could render the system unavailable, preventing all non-authenticated users from accessing the network until the system is restored.
Technical details
The vulnerability exists in the diagnostic tools component of Cisco ISE and ISE-PIC and is rooted in improper validation of user-supplied input (CWE-78, OS command injection). An authenticated remote attacker with valid administrative credentials can send crafted commands to the web-based management interface to perform command injection attacks on the underlying operating system. Successful exploitation allows arbitrary code execution with root privileges. In single-node deployments, this can render the affected node unavailable, causing a denial of service condition where unauthenticated endpoints cannot access the network. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco ISE <UNKNOWN>
- Cisco ISE-PIC <UNKNOWN>
Timeline
- 2026-09-16: disclosed: Published by Cisco Security Advisory