Remote Command Execution Vulnerability in Cisco Identity Services Engine
CVE-2026-20186

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-20186?

A vulnerability in Cisco Identity Services Engine (ISE) enables an authenticated remote attacker with Read Only Admin credentials to execute arbitrary commands on the operating system of the affected device. This weakness arises from inadequate validation of user-supplied input. By crafting a malicious HTTP request, attackers can gain user-level access and potentially elevate privileges to root. In single-node deployments, this could lead to a denial of service (DoS), making the ISE node unavailable and preventing unauthenticated endpoints from accessing the network until the node is restored.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.