CVE-2026-20148
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20148 is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated remote attacker with valid administrative credentials to read arbitrary files on the underlying operating system. The vulnerability was disclosed on April 15, 2026, as part of Cisco Security Advisory cisco-sa-ise-rce-traversal-8bYndVrZ, which also covers the related critical RCE vulnerability CVE-2026-20147. Affected versions span Cisco ISE 3.1.x through 3.5.x and Cisco ISE-PIC 3.1.0 through 3.4.0. It carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal') and stems from insufficient validation of user-supplied input in the HTTP request handling layer of Cisco ISE and ISE-PIC. An attacker with valid administrative credentials can send a specially crafted HTTP request containing path traversal sequences (e.g., ../ or URL-encoded equivalents) to bypass directory restrictions and access arbitrary files on the underlying OS. Exploitation requires no user interaction and has low attack complexity, though it does require high-privilege (administrative) access. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to read arbitrary files on the underlying operating system of the affected Cisco ISE or ISE-PIC node, resulting in a high confidentiality impact. Sensitive files that could be exposed include configuration files, credentials, certificates, and other data stored on the system. There is no impact to integrity or availability — the attacker cannot modify or delete files, and system operation is not disrupted. The vulnerability affects all Cisco ISE 3.1.x through 3.5.x and ISE-PIC 3.1.0 through 3.4.0 deployments regardless of configuration (Cisco Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and Cisco PSIRT has confirmed no known malicious use of this vulnerability in the wild as of the advisory publication date. The EPSS score is approximately 0.049–0.085%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid administrative credentials, which significantly limits the attacker pool. The vulnerability was reported to Cisco by Jonathan Lein of TrendAI Research (Cisco Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Cisco ISE or ISE-PIC instances running vulnerable versions (3.1.x through 3.5.x for ISE; 3.1.0–3.4.0 for ISE-PIC) using network scanning or asset inventory tools.
  2. Credential acquisition: Obtain valid administrative credentials for the target ISE system through phishing, credential reuse, or insider access — exploitation requires high-privilege (admin-level) authentication.
  3. Authenticate to the ISE web interface: Log in to the ISE administrative web interface or API endpoint using the obtained credentials.
  4. Craft malicious HTTP request: Construct an HTTP request targeting a vulnerable ISE endpoint, embedding path traversal sequences (e.g., ../../etc/passwd or URL-encoded variants such as %2e%2e%2f) in a user-controlled parameter.
  5. Send the request: Submit the crafted request to the affected ISE system. If successful, the server returns the contents of the targeted file outside the intended directory.
  6. Exfiltrate sensitive data: Use the read-file capability to access sensitive files such as configuration files, private keys, or credential stores on the underlying OS (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Cisco ISE administrative endpoints containing path traversal patterns (e.g., ../, %2e%2e%2f, %2e%2e/) in request parameters or URI paths; unexpected outbound data transfers from ISE nodes.
  • Logs: ISE application or web server access logs showing HTTP requests with traversal sequences in URL paths or query parameters; access to file paths outside expected application directories logged in OS-level audit logs.
  • File System: Evidence of access to sensitive OS files (e.g., /etc/passwd, /etc/shadow, certificate stores, or ISE configuration files) at unusual times or by the ISE web service process.
  • Authentication: Administrative logins from unexpected IP addresses or at unusual times, particularly preceding anomalous HTTP activity (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions that address CVE-2026-20148: ISE 3.1 Patch 11, ISE 3.2 Patch 10, ISE 3.3 Patch 11, ISE 3.4 Patch 6, and ISE 3.5 Patch 3. Cisco ISE-PIC 3.4 is the last supported release (end-of-sale). There are no workarounds available — upgrading to a fixed release is the only remediation. As an interim measure, organizations should restrict administrative access to ISE systems to authorized personnel only and monitor for suspicious HTTP activity from admin accounts (Cisco Advisory).

Community reactions

Coverage of CVE-2026-20148 was largely bundled with the more severe companion vulnerability CVE-2026-20147 (CVSS 9.9 RCE), which dominated media attention. Outlets including Heise, CyberSecurityNews, CyberPress, and Computerworld reported on the Cisco ISE advisory batch, emphasizing the critical RCE risk. The path traversal flaw (CVE-2026-20148) received less individual focus given its Medium severity and administrative credential requirement. Security aggregators such as Tenable, Qualys, and WaterISAC included it in weekly vulnerability digests. Community sentiment on platforms like Mastodon and Bluesky noted the importance of patching ISE given its role as a network access control platform (Heise, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management