ZeroHour

CVE-2026-20305

large

Authenticated command injection to root in Cisco ISE and ISE-PIC diagnostic tools

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

A command injection flaw (CWE-78) exists in the diagnostic tools of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), caused by improper validation of user-supplied input. An authenticated remote attacker who already holds valid administrative credentials can send crafted commands through the web-based management interface to inject commands into the underlying operating system. A successful exploit yields arbitrary code execution and elevation to root on the affected node. Organizations running ISE or ISE-PIC are affected; in single-node deployments, exploitation can render the ISE node unavailable, blocking endpoints that have not yet authenticated from accessing the network. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed.

What to do: Upgrade ISE and ISE-PIC nodes to the fixed releases identified in the Cisco security advisory for CVE-2026-20305, as no workaround is described in the available data. Because valid admin credentials are required, restrict access to the web-based management interface, review and rotate administrative credentials, and audit admin activity logs for unexpected diagnostic-tool commands. Treat single-node deployments as higher risk given the potential denial-of-service impact on network access.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
largetens of thousands of enterprise deployments, with only a small fraction of management interfaces internet-exposed — Cisco ISE is one of the most widely deployed enterprise NAC/policy platforms across large enterprises, universities and government networks (plausibly tens of thousands of installations), but it is typically deployed on internal networks,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.