CVE-2026-20283
Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability
Description
A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
In plain language
AI Act nowThis is a serious flaw in Cisco Identity Services Engine Software that could let someone with an administrator account take control of the system; act now because a public exploit is available.
Authenticated remote command injection (CWE-78) in the Cisco Identity Services Engine Software IPsec Open API can enable arbitrary OS command execution, with a straightforward path to root privileges.
What to do now
- Check whether you run Cisco Identity Services Engine Software with more than one network connection and an active IPsec tunnel.
- Identify and review all administrator accounts; remove unused accounts, require strong sign-in protection, and restrict administrator access to trusted networks.
- Cisco has not published fixed-version information yet; ask Cisco or your support provider for the affected releases and the first fixed version.
- Until a fix is available, disable or restrict access to the IPsec Open API where business operations allow it.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20283 and every CVE in our database. Create a free account — no credit card required.
Create Free Account