Executive brief
Cisco Identity Services Engine (ISE) is a network access control platform used to manage device authentication and authorization on corporate networks. A vulnerability in its REST API allows authenticated administrators with valid credentials to inject arbitrary commands and gain root-level access, potentially causing the system to become unavailable and blocking new endpoints from accessing the network.
Technical details
The vulnerability is a command injection flaw (CWE-78) in the REST API of Cisco ISE and ISE-PIC, caused by improper validation of user-supplied input. An authenticated remote attacker with administrative credentials can send crafted commands to the web-based management interface to execute arbitrary code with root privileges. Attack requires valid administrative credentials and network access to the management interface. Successful exploitation allows arbitrary code execution as root and privilege escalation; in single-node deployments, exploitation can cause DoS conditions preventing unauthenticated endpoints from accessing the network. Cisco has released software updates to address this vulnerability with no workarounds available.
Affected products
- Cisco Identity Services Engine
- Cisco ISE Passive Identity Connector
Timeline
- 2026-09-16: disclosed