Executive brief
Cisco Identity Services Engine (ISE) is a network access control solution that manages user and device authentication. An unauthenticated attacker can craft a malicious link that, when clicked by an ISE administrator, executes arbitrary JavaScript code in their browser session. This could allow theft of session cookies, sensitive configuration data, or modification of ISE policies without the user's knowledge.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability (CWE-79) in the web-based management interface of Cisco ISE caused by improper input validation. The vulnerability requires network access to the ISE web interface and social engineering to convince an authenticated user to click a crafted link containing malicious script payload. An attacker can execute arbitrary JavaScript in the browser context of an ISE administrator, potentially stealing session tokens, accessing sensitive browser-based data, or performing unauthorized configuration changes. Patches are available for ISE 3.3 (Patch 12), 3.4 (Patch 7), and 3.5 (Patch 4); users on ISE 3.2 and earlier must upgrade to a newer release.
Affected products
- Cisco Identity Services Engine 3.2 and earlier, 3.3 (before Patch 12), 3.4 (before Patch 7), 3.5 (before Patch 4)
Timeline
- 2026-09-16: disclosed