Description
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.

This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials.
Published: 2026-09-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Configuration Modification
Action: Apply Patch
AI Analysis

Impact

A flaw in the web‑based management interface of Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE‑PIC) allows an attacker with valid administrator credentials to send crafted HTTP requests that bypass server‑side permission checks. By exploiting this weakness an attacker can alter configuration entries, such as the descriptions of files displayed on a particular page, effectively changing how the system is presented and potentially turning legitimate configuration into a malicious one. The vulnerability demonstrates a classic authorization bypass (CWE‑285) and does not allow arbitrary code execution or denial of service.

Affected Systems

The vulnerability affects Cisco’s ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific version numbers are listed, implying that all released versions prior to the patch are susceptible. Administrators should verify whether their deployed ISE or ISE‑PIC images match the affected release set advertised in Cisco’s advisory.

Risk and Exploitability

The CVSS score of 4.3 places this flaw in the medium severity range, and an EPSS score of less than 1% indicates a very low exploitation probability under current conditions. The issue is not listed in CISA’s KEV catalog, suggesting no active exploitation campaigns reported yet. Nevertheless, because the attack requires authentic administrator credentials, the threat surface is limited to attackers who have already compromised or stolen such credentials, or who successfully lure an admin into authenticating to a malicious endpoint. If the environment does not enforce MFA or strict administrative role separation, the risk escalates, and patching is strongly advised.

Generated by OpenCVE AI on September 18, 2026 at 00:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest Cisco ISE and ISE‑PIC firmware or patch that addresses the authorization check flaw, as detailed in Cisco’s security advisory.
  • Restrict administrative privileges by disabling unused admin accounts, enforcing multi‑factor authentication, and applying the principle of least privilege for configuration changes.
  • Configure logging and alerting for configuration modification events, and review change logs for any unexpected edits to the ISE management pages.
  • As a temporary mitigation, limit external access to the web‑based management interface to trusted internal networks or specific IP ranges using firewall or ACL rules.

Generated by OpenCVE AI on September 18, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of&nbsp;Administrator&nbsp;permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid&nbsp;Administrator credentials.
Title Cisco Identity Services Engine Authorization Bypass Vulnerability
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Cisco Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T14:45:31.111Z

Reserved: 2025-10-08T11:59:15.404Z

Link: CVE-2026-20285

cve-icon Vulnrichment

Updated: 2026-09-18T14:36:32.359Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:09.217

Modified: 2026-09-18T15:17:07.147

Link: CVE-2026-20285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:38:18Z

Weaknesses