Description
A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. 

This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system. 
To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel.
Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch Urgently
AI Analysis

Impact

A flaw in the IPsec Open API endpoint of Cisco Identity Services Engine allows an authenticated remote attacker to inject operating‑system commands through insufficient input validation, a classic command injection weakness identified as CWE‑78. Successful exploitation gives the attacker the same privileges as the authenticated user and, under Cisco’s own assessment, it is straightforward to elevate those rights to root. The vulnerability is expressly noted as having a high security impact rating because of that privilege escalation path.

Affected Systems

The affected product is Cisco Identity Services Engine Software. No specific version range is supplied, so any deployment that enables the IPsec Open API and runs the vulnerable code is at risk. Because the advisory does not list versions, administrators should verify whether the exposed API is present on their systems.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate‑to‑high severity, while the EPSS score of less than 1% indicates that the likelihood of public exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploiting it requires valid administrative credentials and a node that has more than one network interface, with at least one active IPsec tunnel. The attacker would need remote network access to the IPsec Open API endpoint, which is typically reachable over the management interface; this is an inferred but likely attack vector based on the description.

Generated by OpenCVE AI on September 18, 2026 at 00:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco ISE security patch that fixes the command‑injection issue as soon as it becomes available
  • Restrict access to the IPsec Open API endpoint to trusted administrators or internal network segments only
  • Configure strict input validation or enable WAF rules that block suspicious command patterns on the affected interfaces

Generated by OpenCVE AI on September 18, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.&nbsp; This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.&nbsp; To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Title Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:22.284Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20283

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:39.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:08.970

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')