Description
A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: 1.4% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to send specially crafted data to the REST API of Cisco Identity Services Engine and its Passive Identity Connector. Improper validation of that data leads to command injection on the underlying operating system. Successful exploitation enables the attacker to run arbitrary commands with root privileges and, in single‑node environments, can bring the node down, causing a denial of service that affects network access for unauthenticated endpoints.

Affected Systems

The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software, as published by Cisco. No specific version numbers are listed in the advisory; any installation of these products with the unpatched REST API is susceptible.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, and the EPSS score of 1% shows that the vulnerability has a low but non‑trivial chance of being exploited in the wild. The vulnerability requires a valid administrative credential and access to the externally exposed REST API, making it an authenticated, remote attack vector. Because it can lead to privileged code execution, it represents a critical risk for any ISE deployment not yet patched, but it is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 18, 2026 at 01:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Cisco ISE and ISE-PIC software to the latest Cisco‑released patch that addresses the command injection flaw.
  • Restrict administrative access to the REST API by enforcing strong authentication and, if feasible, limiting exposure to trusted management network segments.
  • Disable the vulnerable REST API endpoint or block inbound traffic to it until a patch is applied (temporary workaround).
  • Conduct a thorough audit of administrative credentials, ensuring least‑privilege principals and periodic rotation.
  • Enable logging and real‑time monitoring for anomalous REST API calls that may indicate attempted exploitation.

Generated by OpenCVE AI on September 18, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Title Cisco Identity Services Engine Command Injection Vulnerability
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T03:57:23.320Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20306

cve-icon Vulnrichment

Updated: 2026-09-16T17:19:03.280Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:16.857

Modified: 2026-09-17T04:17:40.777

Link: CVE-2026-20306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:42Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')