Executive brief
Cisco Identity Services Engine (ISE) is a network access control solution used to authenticate and manage devices connecting to corporate networks. A critical flaw in its web-based management interface allows authenticated administrators with low privileges to execute arbitrary code on the device and gain root access. Successful exploitation could also render single-node ISE deployments unavailable, preventing network access for unauthenticated endpoints until service is restored.
Technical details
CVE-2026-20307 is an insecure Java deserialization vulnerability (CWE-502) in Cisco ISE's web-based management interface. An attacker with low-privileged administrative credentials can exploit this by sending a crafted serialized Java object to the affected device. The vulnerability allows remote, unauthenticated code execution with no user interaction required (CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). A successful exploit grants arbitrary code execution and privilege escalation to root, potentially causing complete device compromise or denial of service in single-node deployments. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine
Timeline
- 2026-09-16: disclosed