SSID BYOD Onboarding Vulnerability in Cisco Identity Services Engine
CVE-2026-20071

3.8LOW

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20071?

A security flaw in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco Identity Services Engine (ISE) enables an adjacent attacker to hijack the onboarding session of an authenticated user. This vulnerability arises from inadequate authentication checks during the user onboarding process, allowing an attacker to spoof a legitimate user and redirect them to a guest web portal. Exploitation of this security issue could lead to unauthorized access to sensitive 802.1X network resources, jeopardizing overall network integrity and security.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.