CVE-2026-20306
large1· 1 readAuthenticated Command Injection to Root RCE in Cisco ISE and ISE-PIC REST API
Cisco ISE and ISE-PIC contain a command injection vulnerability (CWE-78) in their REST API, caused by improper validation of user-supplied input. An authenticated, remote attacker who already holds valid administrative credentials can send crafted commands to the web-based management interface to trigger the flaw. Successful exploitation allows arbitrary code execution on the underlying operating system with elevation to root privileges. In single-node deployments, exploitation can also render the ISE node unavailable, denying network access to endpoints that have not yet authenticated. As of the latest data, the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade ISE and ISE-PIC to the fixed releases identified in the Cisco Security Advisory (version numbers not provided in available data). Until patched, restrict access to the management and REST API interfaces to trusted admin networks, audit and rotate privileged administrative credentials (since valid admin creds are required for exploitation), and enable MFA for ISE administrators. Organizations running single-node deployments should prioritize patching and maintain backups, as exploitation could take the sole node offline and block new endpoint authentication.
| Cisco Identity Services Engine (ISE) | — |
| Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.