Description
A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: 1.4% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper validation of input supplied to the diagnostic tools in Cisco Identity Services Engine and its Passive Identity Connector. An attacker who possesses valid administrative credentials can send specially crafted commands through the web‑based management interface, allowing the execution of arbitrary operating‑system commands with root privileges. Consequently, the attacker can gain full control of the device and, in single‑node deployments, render the affected node unavailable, causing a denial of service for all endpoints that have not yet authenticated.

Affected Systems

Cisco devices including the Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software are affected. Version information is not specified in the available data.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, while the EPSS score of 1% suggests a low to moderate likelihood of exploitation. The vulnerability is listed as not included in the CISA KEV catalog. Exploitation requires remote access to the web interface and authenticated administrative privileges, indicating that the attack vector is remote, authenticated web‑based management. If an attacker succeeds, they can gain root level access and potentially cause a denial of service in single‑node deployments.

Generated by OpenCVE AI on September 18, 2026 at 01:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco ISE firmware update that addresses the command injection issue.
  • Limit access to the web‑based management interface to trusted network segments and enforce multi‑factor authentication for all administrative accounts.
  • Disable or restrict the use of the diagnostic tools until a vendor patch is available, and monitor logs for suspicious command execution attempts.

Generated by OpenCVE AI on September 18, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Title Cisco Identity Services Engine Command Injection Vulnerability
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T03:57:22.261Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20305

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:25.675Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:16.707

Modified: 2026-09-17T04:17:40.540

Link: CVE-2026-20305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:40Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')