
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20136 is a command injection vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, local attacker with administrative privileges to escalate privileges to root on the underlying operating system. Disclosed on April 15, 2026, the vulnerability affects Cisco ISE versions 3.1.0 through 3.5.x (including all patches up to 3.3 Patch 10, 3.4 Patch 5, and 3.5 Patch 2) and ISE-PIC. It carries a CVSS v3.1 base score of 6.0 (Medium) (Cisco Advisory, GitHub Advisory). The vulnerability was reported by Kentaro Kawane of GMO Cybersecurity by Ierae (Cisco Advisory).
The root cause is classified as CWE-116 (Improper Encoding or Escaping of Output), stemming from insufficient validation of user-supplied input passed to a specific CLI command in Cisco ISE and ISE-PIC (Cisco Advisory, GitHub Advisory). An attacker exploits this by providing crafted input to the vulnerable CLI command, causing the underlying operating system to execute injected commands with elevated (root) privileges. Exploitation requires local access and existing administrative-level credentials on the ISE system — there is no remote or unauthenticated attack path. No specific CLI command or payload details have been publicly disclosed (Cisco Advisory).
Successful exploitation allows an authenticated administrator to escalate privileges to root on the underlying operating system of the ISE appliance, granting complete control over the ISE infrastructure. This could result in compromise of network authentication services and identity management for the entire organization, as ISE is commonly used as a central policy and access control platform. The confidentiality and integrity impacts are rated High, while availability is not directly affected by this vulnerability (Cisco Advisory, GitHub Advisory). An attacker with root access could potentially pivot to connected network infrastructure, exfiltrate sensitive identity data, or tamper with authentication policies (Feedly).
As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code is known to exist (Cisco Advisory). The EPSS score is approximately 0.043–0.05%, indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for local access and existing administrative privileges, significantly limiting the attacker pool.
;, |, or backticks) designed to bypass the insufficient input validation.;, |, backticks) or unexpected arguments; OS-level logs showing commands executed as root by the ISE service account outside normal administrative activity.curl, wget, nc), or file manipulation tools not associated with normal ISE operations./etc/, /root/, /tmp/) created by the ISE process or root account outside of patch/upgrade windows; unexpected cron jobs or scheduled tasks added under the root account.Cisco has released fixed software versions to address this vulnerability: ISE/ISE-PIC 3.3 Patch 11 (April 2026), 3.4 Patch 6 (April 2026), and 3.5 Patch 3 (Cisco Advisory). There are no workarounds available — upgrading to a fixed release is the only remediation. As interim risk-reduction measures, organizations should restrict CLI access to only essential personnel, enforce strong access controls and monitoring for administrative accounts, and apply the principle of least privilege (Feedly). Network segmentation to limit local access to ISE platforms is also recommended.
Cisco PSIRT credited Kentaro Kawane of GMO Cybersecurity by Ierae for responsibly disclosing the vulnerability (Cisco Advisory). The vulnerability was noted in the CISA weekly vulnerability bulletin for the week of April 13, 2026, and included in threat landscape digests by security monitoring services. No significant public controversy or notable researcher commentary beyond standard tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."