CVE-2026-20146
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20146 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to read or delete arbitrary files on the underlying operating system. The vulnerability was disclosed on July 15, 2026, and affects Cisco ISE and ISE-PIC versions from 3.1.x through 3.5.x (including all patches up to the fixed releases). It carries a CVSS v3.1 base score of 5.5 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker exploits this by sending a crafted HTTP request containing path traversal sequences (e.g., ../) that bypass the application's input validation, causing the server to resolve file paths outside the intended restricted directory. Exploitation requires valid administrative credentials, meaning the attacker must already be authenticated to the ISE management interface. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).

Impact

A successful exploit allows an authenticated remote attacker to read sensitive files from the underlying operating system — potentially exposing credentials, configuration data, certificates, or other security-sensitive information stored on the ISE appliance — or to delete arbitrary files, which could disrupt ISE operations or degrade its integrity. Since Cisco ISE is a central network access control and policy enforcement platform, compromise of its file system could have downstream effects on network authentication, authorization, and accounting (AAA) infrastructure. Availability is not directly impacted by this vulnerability, but file deletion could indirectly cause service disruption (Cisco Advisory).

Exploitability

As of the advisory publication date (July 15, 2026), Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.48%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Jonathan Lein of TrendAI Research (Cisco Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain Administrative Credentials: Acquire valid administrative credentials for the target Cisco ISE or ISE-PIC management interface through phishing, credential stuffing, or insider access — exploitation requires high-privilege authentication.
  2. Authenticate to ISE Management Interface: Log in to the ISE web-based management interface or API endpoint using the obtained credentials.
  3. Craft Malicious HTTP Request: Construct an HTTP request targeting a vulnerable ISE endpoint, embedding path traversal sequences (e.g., ../../etc/passwd or ../../opt/cisco/ise/logs/) in a user-controlled parameter that is passed to a file system operation.
  4. Send Request and Observe Response: Submit the crafted request to the affected ISE system. If successful, the server returns the contents of the targeted file (for read operations) or confirms deletion (for delete operations).
  5. Exfiltrate or Manipulate Files: Use the traversal to read sensitive files such as configuration files, private keys, or credential stores, or delete critical files to disrupt ISE functionality (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to ISE management endpoints containing encoded path traversal sequences (e.g., %2e%2e%2f, ../, ..%2f) in URL parameters or request bodies; administrative API calls from unexpected source IP addresses.
  • Logs: ISE application logs showing HTTP requests with path traversal patterns resulting in file access outside expected directories; access log entries for file paths not associated with normal ISE operations (e.g., /etc/, /opt/cisco/ise/logs/ accessed via web requests).
  • File System: Unexpected deletion or modification of system files; missing configuration or log files that should be present on the ISE appliance.
  • Process/Behavior: Administrative sessions initiated from unusual geographic locations or at unusual times, particularly followed by file access or deletion activity (Cisco Advisory).

Mitigation and workarounds

Cisco has confirmed that no workarounds are available for this vulnerability. Fixed releases are scheduled for September 2026: ISE/ISE-PIC 3.3 Patch 12, ISE 3.4 Patch 7 (or hot patch), and ISE 3.5 Patch 4 (or hot patch). Deployments running versions earlier than 3.3 should migrate to a supported fixed release. In the interim, organizations should restrict administrative access to ISE management interfaces to only trusted personnel and networks, implement network segmentation to limit exposure of ISE management interfaces, and monitor ISE logs for suspicious file access or deletion patterns (Cisco Advisory).

Community reactions

The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research. Community discussion appeared on Reddit (r/sysadmin and r/security) shortly after disclosure, with posts noting the administrative credential requirement as a significant mitigating factor. Security aggregators including VulnDB, Tenable (Nessus plugin 327091), and threat intelligence platforms indexed the advisory promptly. No major vendor statements beyond the Cisco advisory or notable researcher commentary beyond the discoverer credit have been identified (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management