← All Advisories

CVE-2026-20181

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-20181

Key Details

CVECVE-2026-20181
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsCisco Identity Services Engine, Cisco Identity Services Engine Passive Identity Connector, Cisco Cisco Identity Services Engine Software, and Cisco Cisco ISE Passive Identity Connector
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIdentity Services Engine
CiscoIdentity Services Engine Passive Identity Connector
CiscoCisco Identity Services Engine Software
CiscoCisco ISE Passive Identity Connector
SubsystemsIndustrial Network - Routers/Firewalls
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. (NVD)

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20181
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20181
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv