Description
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain system-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an authenticated, remote attacker with high‑privileged ISE administrative credentials to execute arbitrary system commands. Insufficient validation of user‑supplied input on the HTTP interface permits the attacker to send a crafted request that is interpreted as shell commands, resulting in remote code execution. The flaw is identified as CWE‑77, leading to potential full system compromise and privilege escalation, and can additionally cause a denial‑of‑service if a single ISE node becomes unavailable.

Affected Systems

This issue affects Cisco Identity Services Engine Software. No specific version ranges are provided in the advisory, but all deployments running a vulnerable ISE installation are impacted. Administrators should verify the exact build against the Cisco security advisory for the appropriate fix.

Risk and Exploitability

The CVSS score of 9.1 classifies this as a critical vulnerability, yet the EPSS score of <1% indicates a very low probability of current exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Successful exploitation requires the attacker to possess valid high‑privilege ISE credentials, meaning that the threat is primarily insider or an attacker that has compromised a legitimate account. Attackers can trigger the remote code execution by dispatching a specially crafted HTTP request, and in single‑node deployments, the effect may include a denial‑of‑service that blocks network access for endpoints that have not yet authenticated.

Generated by OpenCVE AI on September 18, 2026 at 00:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cisco Identity Services Engine to the latest release that includes the fix for CVE‑2026‑20176, as identified in Cisco's security advisory.
  • Restrict administrative HTTP access to ISE by implementing IP whitelisting or placing the ISE node behind a firewall that limits exposure only to trusted management networks.
  • Enforce strong password policies and multi‑factor authentication for all ISE administrative accounts to reduce the risk of credential compromise that would allow the attack.

Generated by OpenCVE AI on September 18, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain system-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Title Cisco Identity Services Engine Remote Code Execution Vulnerability
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:23.283Z

Reserved: 2025-10-08T11:59:15.392Z

Link: CVE-2026-20176

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:53.306Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:21.747

Modified: 2026-09-17T12:17:25.200

Link: CVE-2026-20176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:19Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')