Authenticated command injection to root in Cisco ISE and ISE-PIC diagnostic tools
AI analysis
A command injection flaw (CWE-78) exists in the diagnostic tools of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), caused by improper validation of user-supplied input. An authenticated remote attacker who already holds valid administrative credentials can send crafted commands through the web-based management interface to inject commands into the underlying operating system. A successful exploit yields arbitrary code execution and elevation to root on the affected node. Organizations running ISE or ISE-PIC are affected; in single-node deployments, exploitation can render the ISE node unavailable, blocking endpoints that have not yet authenticated from accessing the network. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed.
What to do: Upgrade ISE and ISE-PIC nodes to the fixed releases identified in the Cisco security advisory for CVE-2026-20305, as no workaround is described in the available data. Because valid admin credentials are required, restrict access to the web-based management interface, review and rotate administrative credentials, and audit admin activity logs for unexpected diagnostic-tool commands. Treat single-node deployments as higher risk given the potential denial-of-service impact on network access.
Affected
| Cisco Identity Services Engine (ISE) | — |
| Cisco ISE Passive Identity Connector (ISE-PIC) | — |
Estimated exposure
largetens of thousands of enterprise deployments, with only a small fraction of management interfaces internet-exposed — Cisco ISE is one of the most widely deployed enterprise NAC/policy platforms across large enterprises, universities and government networks (plausibly tens of thousands of installations), but it is typically deployed on internal networks,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.