Description
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system.
To exploit this vulnerability, the attacker must have valid administrative credentials.
Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Published: 2026-09-16
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Cisco ISE allows an authenticated, remote attacker to obtain write access on the underlying operating system through insufficient validation of user‑supplied HTTP input. The attacker must possess valid administrative credentials and can send a crafted HTTP request to the device. Successful exploitation grants the attacker write capability to the OS, which can be leveraged to gain root privileges, enabling arbitrary code execution and full system compromise. The CVE's Security Impact Rating is High because reaching root is considered easy once write access is achieved.

Affected Systems

Cisco Identity Services Engine Software is the affected product. Specific version information is not provided in the advisory; any current or older version of Cisco ISE that has not been patched may be vulnerable.

Risk and Exploitability

The CVSS score is 4.9, indicating a moderate severity, but the CMS assigned a High impact rating because the privilege escalation potential is high. The EPSS score is less than 1%, suggesting a low current exploitation probability. Attackers must be authenticated with valid administrative credentials and must craft a malicious HTTP request to trigger the flaw. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploit activity is reported at this time.

Generated by OpenCVE AI on September 18, 2026 at 00:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Cisco Identity Services Engine to the latest version that includes the patch for this vulnerability.
  • Enforce strict access controls by limiting administrative credentials to trusted personnel and using strong authentication methods.
  • Configure network segmentation and firewall rules to restrict external HTTP access to the ISE management interface, reducing the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials. Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Title Cisco Identity Services Engine Authenticated Write Vulnerability
Weaknesses CWE-641
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-22T20:29:45.156Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20282

cve-icon Vulnrichment

Updated: 2026-09-22T20:24:49.882Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:08.837

Modified: 2026-09-22T21:17:30.440

Link: CVE-2026-20282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-641

    Improper Restriction of Names for Files and Other Resources