Arbitrary Command Execution Vulnerability in Cisco Identity Services Engine
CVE-2026-20181

9.1CRITICAL

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20181?

A vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC may allow an authenticated remote attacker to execute arbitrary commands on the device's underlying operating system. This flaw arises from insufficient validation of user-supplied input, permitting the attacker, who possesses valid administrative credentials, to dispatch a specially crafted HTTP request to exploit the vulnerability. If successful, the attacker can gain user-level access to the operating system and escalate privileges to root. In single-node deployments, this exploitation can lead to a denial of service (DoS) condition, causing the affected ISE node to be unavailable and preventing unauthenticated endpoints from accessing the network until the node is restored.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.