Status: EPSS-IMMINENT | Advisory ID: CVE-2026-20147
| CVE | CVE-2026-20147 |
| CVSS Score / Version | 9.9 (Critical) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector |
| Classified as | CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')) |
| Exploitation prediction (EPSS) | 10.38% probability of exploitation in the next 30 days (96% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Cisco | Identity Services Engine | ||
| Cisco | Identity Services Engine Passive Identity Connector |
| Subsystems | Industrial Network - Routers/Firewalls |
| Sectors | Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems |
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Monitor Cisco's web page for any future patch releases. See vendor advisory link below.