Arbitrary Command Execution Vulnerability in Cisco ISE Management Interface
CVE-2026-20307
What is CVE-2026-20307?
A serious vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE), allowing an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This issue stems from insecure deserialization of user-supplied Java byte streams. By sending a maliciously crafted serialized Java object to the management interface, an attacker could gain the ability to run arbitrary code on the device. In single-node setups, successful exploitation can make the impacted ISE node unavailable, resulting in denial of service (DoS) and preventing unauthenticated endpoints from accessing the network until restoration.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3