Command Injection Vulnerability in Cisco Identity Services Engine and ISE-PIC
CVE-2026-20136

6MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-20136?

A command injection vulnerability exists in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). An authenticated local attacker with administrative privileges can exploit this flaw by sending specially crafted input to a specific CLI command. This leads to insufficient validation of the user-supplied input, enabling the attacker to execute commands on the underlying operating system and potentially elevate their privileges to root, resulting in significant unauthorized access.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.