
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20146 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to read or delete arbitrary files on the underlying operating system. The vulnerability was disclosed on July 15, 2026, and affects Cisco ISE and ISE-PIC versions from 3.1.x through 3.5.x (including all patches up to the fixed releases). It carries a CVSS v3.1 base score of 5.5 (Medium) (Cisco Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker exploits this by sending a crafted HTTP request containing path traversal sequences (e.g., ../) that bypass the application's input validation, causing the server to resolve file paths outside the intended restricted directory. Exploitation requires valid administrative credentials, meaning the attacker must already be authenticated to the ISE management interface. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).
A successful exploit allows an authenticated remote attacker to read sensitive files from the underlying operating system — potentially exposing credentials, configuration data, certificates, or other security-sensitive information stored on the ISE appliance — or to delete arbitrary files, which could disrupt ISE operations or degrade its integrity. Since Cisco ISE is a central network access control and policy enforcement platform, compromise of its file system could have downstream effects on network authentication, authorization, and accounting (AAA) infrastructure. Availability is not directly impacted by this vulnerability, but file deletion could indirectly cause service disruption (Cisco Advisory).
As of the advisory publication date (July 15, 2026), Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.48%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Jonathan Lein of TrendAI Research (Cisco Advisory, GitHub Advisory).
../../etc/passwd or ../../opt/cisco/ise/logs/) in a user-controlled parameter that is passed to a file system operation.%2e%2e%2f, ../, ..%2f) in URL parameters or request bodies; administrative API calls from unexpected source IP addresses./etc/, /opt/cisco/ise/logs/ accessed via web requests).Cisco has confirmed that no workarounds are available for this vulnerability. Fixed releases are scheduled for September 2026: ISE/ISE-PIC 3.3 Patch 12, ISE 3.4 Patch 7 (or hot patch), and ISE 3.5 Patch 4 (or hot patch). Deployments running versions earlier than 3.3 should migrate to a supported fixed release. In the interim, organizations should restrict administrative access to ISE management interfaces to only trusted personnel and networks, implement network segmentation to limit exposure of ISE management interfaces, and monitor ISE logs for suspicious file access or deletion patterns (Cisco Advisory).
The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research. Community discussion appeared on Reddit (r/sysadmin and r/security) shortly after disclosure, with posts noting the administrative credential requirement as a significant mitigating factor. Security aggregators including VulnDB, Tenable (Nessus plugin 327091), and threat intelligence platforms indexed the advisory promptly. No major vendor statements beyond the Cisco advisory or notable researcher commentary beyond the discoverer credit have been identified (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."