Configuration Modification Vulnerability in Cisco Identity Services Engine and ISE-PIC
CVE-2026-20285
4.3MEDIUM
What is CVE-2026-20285?
A vulnerability exists within the web-based management interface of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Due to insufficient server-side validation of Administrator permissions, an authenticated remote attacker can exploit this issue by sending a specifically crafted HTTP request. This exploit allows unauthorized modification of configuration settings, potentially altering file descriptions on affected systems. To successfully exploit this weakness, an attacker must possess valid Administrator credentials.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3