CVE-2026-20146
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20146 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to read or delete arbitrary files on the underlying operating system. The vulnerability was disclosed on July 15, 2026, and affects Cisco ISE and ISE-PIC versions 3.1.x through 3.5.x (prior to the fixed releases). It carries a CVSS v3.1 base score of 5.5 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker can craft a malicious HTTP request containing path traversal sequences (e.g., ../) to escape the intended directory boundary and access or delete arbitrary files on the underlying OS. Exploitation requires valid administrative credentials, meaning the attacker must already be authenticated to the ISE management interface. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).

Impact

A successful exploit could allow an authenticated attacker to read sensitive files — such as configuration files, credentials, or private keys stored on the ISE appliance — or delete arbitrary files, potentially disrupting ISE operations. Since Cisco ISE is a central network access control and policy enforcement platform, compromise of its file system could expose authentication infrastructure, network policy configurations, and identity data, with potential for lateral movement across the network. Availability impact is rated None in the CVSS score, though arbitrary file deletion could indirectly cause service disruption (Cisco Advisory).

Exploitation steps

  1. Credential Acquisition: Obtain valid administrative credentials for the target Cisco ISE or ISE-PIC management interface through phishing, credential stuffing, or insider access.
  2. Authenticate to ISE: Log in to the ISE administrative web interface or API endpoint using the acquired credentials.
  3. Craft Malicious HTTP Request: Construct an HTTP request targeting a vulnerable ISE endpoint, embedding path traversal sequences (e.g., ../../etc/passwd or similar OS-level paths) in a user-supplied parameter that is passed to a file system operation.
  4. Send Request: Submit the crafted request to the affected ISE system. Due to insufficient input validation, the traversal sequences are not sanitized, allowing the request to resolve to a file path outside the intended directory.
  5. Read or Delete Target File: Depending on the endpoint and operation, the attacker can retrieve the contents of sensitive files (e.g., configuration files, certificates, credentials) or delete arbitrary files on the underlying OS (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to ISE management interfaces containing encoded path traversal sequences (e.g., %2e%2e%2f, ../, ..%2f) in URL parameters or request bodies.
  • Logs: ISE application or web server access logs showing requests with path traversal patterns to file-handling endpoints; unexpected file access or deletion events logged by the OS audit subsystem.
  • File System: Missing or unexpectedly modified system or configuration files on the ISE appliance; access timestamps on sensitive files (e.g., /etc/passwd, ISE config files) updated outside of normal maintenance windows.
  • Process/Behavior: Administrative sessions originating from unexpected IP addresses or at unusual times, particularly those making file-related API calls (Cisco Advisory).

Mitigation and workarounds

Cisco has confirmed that no workarounds are available for this vulnerability. Fixed releases are scheduled as follows: ISE/ISE-PIC 3.3 → Patch 12 (September 2026); ISE/ISE-PIC 3.4 → Patch 7 (September 2026) or available hot patch; ISE 3.5 → Patch 4 (September 2026) or available hot patch. Versions earlier than 3.3 should migrate to a fixed release. Until patches are applied, administrators should restrict ISE administrative access to only trusted personnel and trusted IP ranges, implement network segmentation to limit exposure of ISE management interfaces, and monitor ISE logs for suspicious file access or deletion activity (Cisco Advisory).

Community reactions

The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research and was publicly disclosed on July 15, 2026. Community discussion appeared on Reddit's r/sysadmin and r/security shortly after disclosure, with posts noting the administrative credential requirement as a significant mitigating factor. The vulnerability was also picked up by threat intelligence aggregators and weekly digest publications. Overall community sentiment reflects moderate concern given the privileged access requirement and absence of active exploitation (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management