Configuration Modification Vulnerability in Cisco Identity Services Engine and ISE-PIC
CVE-2026-20285

4.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20285?

A vulnerability exists within the web-based management interface of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Due to insufficient server-side validation of Administrator permissions, an authenticated remote attacker can exploit this issue by sending a specifically crafted HTTP request. This exploit allows unauthorized modification of configuration settings, potentially altering file descriptions on affected systems. To successfully exploit this weakness, an attacker must possess valid Administrator credentials.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.