CVE Tools

CVE-2026-20283

Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-78

Description

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.  This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.  To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.

In plain language

AI Act now

This is a serious flaw in Cisco Identity Services Engine Software that could let someone with an administrator account take control of the system; act now because a public exploit is available.

Executive summary

Authenticated remote command injection (CWE-78) in the Cisco Identity Services Engine Software IPsec Open API can enable arbitrary OS command execution, with a straightforward path to root privileges.

If affected, business impact
Identity system takeoverNetwork access disruptionCredential theft riskSecurity policy changesOperational disruption

What to do now

  1. Check whether you run Cisco Identity Services Engine Software with more than one network connection and an active IPsec tunnel.
  2. Identify and review all administrator accounts; remove unused accounts, require strong sign-in protection, and restrict administrator access to trusted networks.
  3. Cisco has not published fixed-version information yet; ask Cisco or your support provider for the affected releases and the first fixed version.
  4. Until a fix is available, disable or restrict access to the IPsec Open API where business operations allow it.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:UC:HI:HA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

Cisco
commercial·USaka cisco systems, cisco systems inc.

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20283 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows