ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability

AI summary · glm-5.3-flash

Cisco Identity Services Engine's PatchUpdateListener has an authenticated directory traversal (CVE-2026-20148, CVSS 4.9) enabling sensitive information disclosure.

ZDI advisory ZDI-26-582 describes a directory traversal information disclosure vulnerability in the PatchUpdateListener component of Cisco Identity Services Engine. Remote attackers can disclose sensitive information, but valid authentication is required to exploit the flaw. ZDI assigned a CVSS rating of 4.9 and CVE-2026-20148.

  • Authenticated directory traversal in Cisco ISE PatchUpdateListener.
  • Allows remote disclosure of sensitive information.
  • CVSS 4.9; tracked as CVE-2026-20148 under ZDI-26-582.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20148
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating syste

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.

NVD description · AI analysis pending
4.97%
  • cisco identity services engine
  • cisco identity services engine passive identity connector
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20148.

This source does not provide full text. Read it at zerodayinitiative.com.