CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-20180

CVSS 9.9v3.1pub. 2026-04-15upd. 2026-07-08

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

🤖 AI Analysis
How it works

The vulnerability stems from insufficient validation of user-supplied data (path traversal, CWE-22). An attacker sends a specially crafted HTTP request to the vulnerable device. As a result of successful exploitation, they gain access to the operating system at the level of a regular user, and can then perform privilege escalation to the root account. Read Only Admin privileges are sufficient to perform the attack.

Impact

An attacker can gain full control over the device's operating system (root access), enabling arbitrary modification of configuration and data. In single-node ISE environments, the attack can cause node unavailability and prevent unauthenticated endpoints from accessing the network (DoS).

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv). Additionally, it is recommended to restrict administrative access to the ISE management interface to trusted hosts only and monitor logs for unauthorized HTTP requests.

Who is affected

Cisco Identity Services Engine (ISE) — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Cisco Identity Services Engine

    APP
    Cisco
    3.2.03.3.03.4.0< 3.2.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSPath Traversal
CWE
References

Related vulnerabilities

CVE-2025-20337CRITICAL10.0⚠ KEVPL ✓same product

Nieuwierzytelniony RCE jako root w Cisco ISE i ISE-PIC poprzez API

CVE-2025-20281CRITICAL10.0⚠ KEVPL ✓same product

Cisco ISE / ISE-PIC — nieuwierzytelniony RCE przez API jako root

CVE-2026-20181CRITICAL9.1PL ✓same product

RCE i privilege escalation w Cisco ISE i ISE-PIC poprzez path traversal

CVE-2026-20147CRITICAL9.9PL ✓same product

RCE z privilege escalation do root w Cisco ISE i ISE-PIC

CVE-2026-20186CRITICAL9.9PL ✓same product

RCE w Cisco ISE — eskalacja uprawnień do root przez HTTP