CVE-2026-20305
Cisco Identity Services Engine Command Injection Vulnerability
Description
A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
In plain language
AI Act nowA serious flaw in Cisco Identity Services Engine software lets someone with an administrator login take over the system; typical businesses using it should act now, but no fixed version is available yet.
Authenticated remote command injection (CWE-78) in Cisco ISE diagnostic tools permits an administrator-level attacker to execute arbitrary operating-system commands and elevate to root.
What to do now
- Check whether your organization runs Cisco Identity Services Engine software, including the Passive Identity Connector, and identify who has administrator access.
- Ask Cisco or your support provider for the vendor-recommended fixed version; no patch or fixed version information is currently available.
- Until a fix is available, restrict the web management interface to a small set of trusted administrator networks and review administrator accounts for unnecessary access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20305 and every CVE in our database. Create a free account — no credit card required.
Create Free Account