ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI publishes three Cisco Identity Services Engine advisories: two authenticated RCE flaws and one XXE information disclosure” — merged summary and timeline →

ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-20176, an authenticated command injection flaw enabling remote code execution in Cisco Identity Services Engine, rated CVSS 7.2.

The Zero Day Initiative published advisory ZDI-26-716 describing a command injection vulnerability in the createDBLink function of Cisco Identity Services Engine. Remote attackers who are authenticated can execute arbitrary code on affected installations. The flaw is tracked as CVE-2026-20176 and carries a CVSS rating of 7.2. No exploitation in the wild is reported in the advisory.

  • Authenticated remote code execution via createDBLink command injection in Cisco ISE.
  • Tracked as CVE-2026-20176 with a CVSS score of 7.2.
  • Disclosure published by ZDI as advisory ZDI-26-716.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20176
Authenticated Command Injection in Cisco Identity Services Engine (ISE)

Cisco ISE contains a command injection flaw (CWE-77) caused by insufficient validation of user-supplied input. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted HTTP request to an affected device to run arbitrary commands on the underlying operating system, gaining system-level access and then elevating to root. In single-node deployments, successful exploitation can render the ISE node unavailable, causing a denial of service in which endpoints that have not yet authenticated cannot access the network until the node is restored. All Cisco ISE deployments are potentially affected, though exploitation requires stolen or compromised administrator credentials rather than anonymous access. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed.

Do: Upgrade to the fixed release specified in Cisco's PSIRT advisory for CVE-2026-20176 (not listed in this data). Until patched, restrict access to the ISE administration interface to trusted management networks, audit high-privileged admin accounts for compromise (since valid admin credentials are required), and monitor for unexpected root-level or shell activity on ISE appliances. Operators of single-node deployments should prepare failover/restore plans, as exploitation would block new endpoint network authentication until the node is recovered.

9.1
  • Cisco Identity Services Engine (ISE)
largelikely tens of thousands of enterprise ISE deployments/nodes worldwide (estimated)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.

This source does not provide full text. Read it at zerodayinitiative.com.