ZeroHour

CVE-2026-20287

large

Improper Privilege Management Issues in Cisco Identity Services Engine (ISE) and ISE-PIC

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-20287 covers multiple improper privilege management flaws (CWE-269) in Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC), discovered during a comprehensive internal security review by Cisco's engineering teams and addressed in a software hardening release. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the flaws can be triggered over the network without user interaction, but only by an attacker who already holds high privileges on the system, such as an administrative or similarly privileged account. Successful exploitation yields high confidentiality and integrity impact — unauthorized access to and modification of privileged functionality or identity data — with no availability impact, for a medium severity score of 6.5. Any organization running Cisco ISE or ISE-PIC is potentially affected, though Cisco has not published specific affected or fixed version ranges in the available data. No public proof-of-concept or CISA KEV listing exists for this CVE and no exploitation of it is known, but Cisco has separately warned of an actively exploited ISE zero-day authentication bypass (CVSS 10.0), which raises the urgency of patching ISE deployments.

What to do: Upgrade Cisco ISE and ISE-PIC to the fixed versions named in Cisco's advisory for CVE-2026-20287 (the software hardening release), as no version ranges appear in the available data. Restrict administrative access to ISE/ISE-PIC management interfaces to trusted management networks, and audit privileged accounts and configuration-change logs for unexpected privilege changes. Because Cisco has also warned of a separate actively exploited zero-day ISE auth bypass, treat ISE patching as urgent and verify no ISE admin or API interfaces are reachable from untrusted networks.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
largelikely tens of thousands of enterprise ISE/ISE-PIC deployments worldwide, with far fewer internet-exposed instances — Cisco ISE is a mainstream enterprise network access control and identity platform commonly deployed by large organizations, typically on internal management networks rather than exposed to the internet, and no public install-base metric…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20287 are related to improper privilege managment issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-269.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.