Command Injection Vulnerability in Cisco ISE and ISE-PIC Products
CVE-2026-20305
9.1CRITICAL
What is CVE-2026-20305?
A command injection vulnerability exists in the diagnostic tools of Cisco ISE and ISE-PIC, allowing an authenticated remote attacker to send specially crafted commands through the web-based management interface. This can lead to unauthorized execution of arbitrary code and may elevate privileges to root. Successful exploitation may cause the affected ISE node to become unavailable, potentially resulting in a denial of service for unmatched endpoints trying to access the network until the node is restored. Proper security measures should be implemented to mitigate this risk.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3