Description
A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks.  

This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.
Published: 2026-09-16
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Session Hijack via insufficient authentication in BYOD onboarding
Action: Apply Patch
AI Analysis

Impact

A flaw in the SSID bring-your-own-device onboarding workflow of Cisco Identity Services Engine allows an attacker to impersonate a legitimate user and hijack the onboarding session, granting unauthorized access to protected 802.1X networks. The weakness is a lack of proper authentication checks while a user is being onboarded, enabling session takeover. The impact is limited to gaining access to the target user's network resources, but it could be used to laterally move within the environment if the protected network hosts critical assets.

Affected Systems

The vulnerability affects Cisco Identity Services Engine Software. No specific versions are enumerated in the advisory, so all supported releases should be evaluated against the vendor’s patch schedule.

Risk and Exploitability

The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the local network who can manipulate the BYOD onboarding flow, as the description infers a lack of authentication checks during the onboarding redirect to the guest web portal.

Generated by OpenCVE AI on September 17, 2026 at 20:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco ISE patch that addresses the BYOD onboarding authentication flaw.
  • If a patch is not immediately available, restrict BYOD onboarding to trusted networks and use network segmentation to isolate the control plane from untrusted devices.
  • Disable or limit the SSID bring-your-own-device service until the issue is resolved, ensuring that only authenticated users can trigger onboarding redirects.

Generated by OpenCVE AI on September 17, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of&nbsp;another user and access protected 802.1X networks. &nbsp; This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering&nbsp;a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.
Title ISE 802.1x Session Hijack Vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T14:05:45.971Z

Reserved: 2025-10-08T11:59:15.357Z

Link: CVE-2026-20071

cve-icon Vulnrichment

Updated: 2026-09-17T14:05:41.575Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.087

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing