
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20146 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to read or delete arbitrary files on the underlying operating system. The vulnerability was disclosed on July 15, 2026, and affects Cisco ISE and ISE-PIC versions 3.1.x through 3.5.x (prior to the fixed releases). It carries a CVSS v3.1 base score of 5.5 (Medium) (Cisco Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker can craft a malicious HTTP request containing path traversal sequences (e.g., ../) to escape the intended directory boundary and access or delete arbitrary files on the underlying OS. Exploitation requires valid administrative credentials, meaning the attacker must already be authenticated to the ISE management interface. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).
A successful exploit could allow an authenticated attacker to read sensitive files — such as configuration files, credentials, or private keys stored on the ISE appliance — or delete arbitrary files, potentially disrupting ISE operations. Since Cisco ISE is a central network access control and policy enforcement platform, compromise of its file system could expose authentication infrastructure, network policy configurations, and identity data, with potential for lateral movement across the network. Availability impact is rated None in the CVSS score, though arbitrary file deletion could indirectly cause service disruption (Cisco Advisory).
../../etc/passwd or similar OS-level paths) in a user-supplied parameter that is passed to a file system operation.%2e%2e%2f, ../, ..%2f) in URL parameters or request bodies./etc/passwd, ISE config files) updated outside of normal maintenance windows.Cisco has confirmed that no workarounds are available for this vulnerability. Fixed releases are scheduled as follows: ISE/ISE-PIC 3.3 → Patch 12 (September 2026); ISE/ISE-PIC 3.4 → Patch 7 (September 2026) or available hot patch; ISE 3.5 → Patch 4 (September 2026) or available hot patch. Versions earlier than 3.3 should migrate to a fixed release. Until patches are applied, administrators should restrict ISE administrative access to only trusted personnel and trusted IP ranges, implement network segmentation to limit exposure of ISE management interfaces, and monitor ISE logs for suspicious file access or deletion activity (Cisco Advisory).
The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research and was publicly disclosed on July 15, 2026. Community discussion appeared on Reddit's r/sysadmin and r/security shortly after disclosure, with posts noting the administrative credential requirement as a significant mitigating factor. The vulnerability was also picked up by threat intelligence aggregators and weekly digest publications. Overall community sentiment reflects moderate concern given the privileged access requirement and absence of active exploitation (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."