
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20186 is a command injection vulnerability in Cisco Identity Services Engine (ISE) that allows an authenticated remote attacker with at least Read Only Admin credentials to execute arbitrary commands on the underlying operating system. It is part of a broader advisory (cisco-sa-ise-rce-4fverepv) that also covers CVE-2026-20180, both discovered during internal security testing by Cisco's Advanced Security Initiatives Group (ASIG). Affected versions span Cisco ISE releases 3.1.x through 3.4.x (including all patch levels up to 3.4 Patch 3); ISE 3.5 and ISE Passive Identity Connector (ISE-PIC) are not affected. The vulnerability was publicly disclosed on April 15, 2026, and carries a CVSS v3.1 base score of 9.9 (Critical) (Cisco Advisory, GitHub Advisory).
The root cause is insufficient validation of user-supplied input, classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'). An attacker exploits this by sending a crafted HTTP request to a vulnerable ISE endpoint; the application fails to sanitize special characters or command delimiters, allowing injected OS commands to be executed by the ISE process. The attack vector is network-based, requires low privileges (Read Only Admin credentials), no user interaction, and has a changed scope — meaning the impact extends beyond the ISE application itself to the underlying OS. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).
Successful exploitation grants the attacker initial user-level access to the underlying operating system of the ISE appliance, which can then be escalated to root privileges, resulting in full system compromise with high confidentiality, integrity, and availability impact. In single-node ISE deployments, exploitation can render the ISE node unavailable, causing a denial of service (DoS) condition where unauthenticated endpoints are blocked from network access until the node is restored. Given ISE's role as a network access control (NAC) and policy enforcement platform, a compromised ISE node could enable lateral movement, credential harvesting, and policy manipulation across the broader enterprise network (Cisco Advisory, GitHub Advisory).
As of the disclosure date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code has been identified (Cisco Advisory). The EPSS score is approximately 0.28–0.38%, placing it in roughly the 60th percentile for exploitation probability within 30 days (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
;, |, &&, or backticks) within the relevant parameter.;, |, &&, backticks) in parameter values./var/log/audit/audit.log) recording unexpected command executions./bin/bash, sh, curl, wget, python); processes running as root that are not part of normal ISE operation.Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Organizations should upgrade to the following fixed releases as soon as possible: ISE 3.2 → 3.2 Patch 8, ISE 3.3 → 3.3 Patch 8, ISE 3.4 → 3.4 Patch 4; ISE releases earlier than 3.2 must migrate to a supported fixed release, and ISE 3.5 is not vulnerable. As interim risk reduction measures, restrict network access to ISE administration interfaces to trusted administrative networks only, enforce strong access controls and audit logging for all admin accounts (including Read Only Admin), and monitor ISE nodes for anomalous command execution activity (Cisco Advisory).
The vulnerability received broad coverage from security media outlets including The Hacker News, BleepingComputer, SecurityWeek, Heise, Security Affairs, and TechRadar, all highlighting the critical severity and the need for immediate patching (The Hacker News, BleepingComputer, SecurityWeek). The Belgian Centre for Cybersecurity (CCB) issued a warning urging organizations to patch immediately, characterizing the ISE vulnerabilities as capable of leading to remote code execution (CCB Advisory). CISA included the vulnerability in its weekly bulletin (SB26-110), and the SANS Internet Storm Center discussed it in a podcast episode. Community sentiment on social media (Bluesky, Mastodon/infosec.exchange) reflected urgency given ISE's critical role in enterprise network access control.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."