Description
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials.

This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from insecure deserialization of a user‑supplied Java byte stream in the web‑based management interface of Cisco Identity Services Engine. An authenticated attacker with low‑privileged administrative rights can send a crafted serialized object that is executed on the host, enabling arbitrary command execution and privilege elevation to root. The flaw can also lead to a denial of service by crashing the ISE node in single‑node deployments, preventing endpoints from authenticating until the system is restored.

Affected Systems

Cisco Identity Services Engine software is affected. The advisory does not list specific build versions, indicating that all current releases that include the vulnerable deserialization logic may be impacted. Administrators should check Cisco’s current patch or upgrade for the ISE product to ensure protection.

Risk and Exploitability

The CVSS score of 9.9 classifies this flaw as critical. Although the EPSS probability is less than 1%, the combination of a high severity score, the requirement for only low‑privileged authentication, and the remote attack vector via the management interface make it a high risk scenario. The vulnerability is not currently in the CISA KEV catalog, yet the potential impact—remote code execution, privilege escalation, and possible service disruption—demands urgent attention.

Generated by OpenCVE AI on September 18, 2026 at 01:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Cisco ISE patch or upgrade that addresses the insecure deserialization flaw.
  • Restrict access to the web‑based management interface to a trusted network segment and enforce strict authentication controls.
  • Disable or neutralize the Java serialization feature on the affected ISE nodes to prevent exploitation of this flaw.

Generated by OpenCVE AI on September 18, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Title Cisco Identity Services Engine Remote Code Execution Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:24.811Z

Reserved: 2025-10-08T11:59:15.409Z

Link: CVE-2026-20307

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:18.715Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:16.973

Modified: 2026-09-17T12:17:25.977

Link: CVE-2026-20307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:37Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data