
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20148 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated remote attacker with valid administrative credentials to read arbitrary files on the underlying operating system. The vulnerability was disclosed on April 15, 2026, as part of Cisco Security Advisory cisco-sa-ise-rce-traversal-8bYndVrZ, which also covers the related critical RCE vulnerability CVE-2026-20147. Affected versions span Cisco ISE 3.1.x through 3.5.x and Cisco ISE-PIC 3.1.0 through 3.4.0. It carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker with valid administrative credentials can send a specially crafted HTTP request containing path traversal sequences (e.g., ../ or URL-encoded equivalents) to bypass directory restrictions and access arbitrary files on the underlying OS. Exploitation requires no user interaction and has low attack complexity, though it does require high-privilege (administrative) access. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker to read arbitrary files on the underlying operating system of the affected Cisco ISE or ISE-PIC node, resulting in a high confidentiality impact. Sensitive files that could be exposed include configuration files, credentials, certificates, and other data stored on the system. There is no impact to integrity or availability — the attacker cannot modify or delete files, and system operation is not disrupted. The vulnerability affects all Cisco ISE 3.1.x through 3.5.x and ISE-PIC 3.1.0 through 3.4.0 deployments regardless of configuration (Cisco Advisory).
No public proof-of-concept exploit code has been identified, and Cisco PSIRT has confirmed no known malicious use of this vulnerability in the wild as of the advisory publication date. The EPSS score is approximately 0.049–0.085%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid administrative credentials, which significantly limits the attacker pool. The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research (Cisco Advisory, GitHub Advisory).
../../etc/passwd or URL-encoded variants such as %2e%2e%2f) in a user-controlled parameter.../, %2e%2e%2f, %2e%2e/) in request parameters or URI paths; unexpected outbound data transfers from ISE nodes./etc/passwd, /etc/shadow, certificate stores, or ISE configuration files) at unusual times or by the ISE web service process.Cisco has released fixed software versions that address CVE-2026-20148: ISE 3.1 Patch 11, ISE 3.2 Patch 10, ISE 3.3 Patch 11, ISE 3.4 Patch 6, and ISE 3.5 Patch 3. Cisco ISE-PIC 3.4 is the last supported release (end-of-sale). There are no workarounds available — upgrading to a fixed release is the only remediation. As an interim measure, organizations should restrict administrative access to ISE systems to authorized personnel only and monitor for suspicious HTTP activity from admin accounts (Cisco Advisory).
Coverage of CVE-2026-20148 was largely bundled with the more severe companion vulnerability CVE-2026-20147 (CVSS 9.9 RCE), which dominated media attention. Outlets including Heise, CyberSecurityNews, CyberPress, and Computerworld reported on the Cisco ISE advisory batch, emphasizing the critical RCE risk. The path traversal flaw (CVE-2026-20148) received less individual focus given its Medium severity and administrative credential requirement. Security aggregators such as Tenable, Qualys, and WaterISAC included it in weekly vulnerability digests. Community sentiment on platforms like Mastodon and Bluesky noted the importance of patching ISE given its role as a network access control platform (Heise, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."