Description
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. 

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Published: 2026-07-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw exists in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector. The flaw originates from improper validation of user-supplied input in HTTP requests. An attacker who holds valid administrative credentials can craft a request that bypasses the check, causing the underlying operating system to resolve a crafted path. Successful exploitation permits the attacker to read or delete arbitrary files on the system, compromising the confidentiality and integrity of the appliance.

Affected Systems

The vulnerability affects Cisco’s Identity Services Engine Software and the ISE Passive Identity Connector. No specific version numbers are listed; all unpatched installations are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% implies a low probability of exploitation. The vulnerability is not included in the CISA KEV catalog. An attacker must be authenticated with administrative privileges, so the exposure is limited to insiders or compromised accounts. Exploitation requires sending a crafted HTTP request; if successful, the attacker can read or delete sensitive files on the appliance’s storage.

Generated by OpenCVE AI on July 31, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco patch that addresses the path traversal flaw in ISE and ISE‑PIC.
  • Restrict administrative credentials to the least set of users and require multi‑factor authentication.
  • Limit the ISE management interface to trusted internal networks and apply firewall or segmentation rules to isolate the appliance from untrusted hosts.

Generated by OpenCVE AI on July 31, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Title Cisco Identity Services Engine Path Traversal Vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Cisco Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-15T17:58:15.091Z

Reserved: 2025-10-08T11:59:15.384Z

Link: CVE-2026-20146

cve-icon Vulnrichment

Updated: 2026-07-15T17:58:11.464Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')