SSID BYOD Onboarding Vulnerability in Cisco Identity Services Engine
CVE-2026-20071
3.8LOW
What is CVE-2026-20071?
A security flaw in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco Identity Services Engine (ISE) enables an adjacent attacker to hijack the onboarding session of an authenticated user. This vulnerability arises from inadequate authentication checks during the user onboarding process, allowing an attacker to spoof a legitimate user and redirect them to a guest web portal. Exploitation of this security issue could lead to unauthorized access to sensitive 802.1X network resources, jeopardizing overall network integrity and security.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3