CVE-2026-20180 Details
Description
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
A remote code execution vulnerability has been identified in Cisco Identity Services Engine (ISE) versions prior to 3.2, 3.2, 3.3, and 3.4. This vulnerability allows an authenticated attacker with Read Only Admin credentials to execute arbitrary commands on the underlying operating system of the affected device. The issue arises from insufficient validation of user-supplied input, enabling exploitation through crafted HTTP requests. Successful exploitation could lead to unauthorized user-level access, with potential escalation to root privileges. In single-node ISE deployments, this vulnerability could cause the node to become unavailable, creating a denial-of-service condition that prevents unauthenticated endpoints from accessing the network until the node is restored.
Users are advised to upgrade to Cisco ISE versions 3.2 Patch 8, 3.3 Patch 8, or 3.4 Patch 4. For instructions on upgrading, see the Upgrade Guides on the Cisco Identity Service Engine support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco identity services engine | < 3.2.0 3.2.0 - 3.2.0 patch1 3.2.0 patch2 3.2.0 patch3 3.2.0 patch4 3.2.0 patch5 3.2.0 patch6 3.2.0 patch7 3.3.0 - 3.3.0 patch1 3.3.0 patch2 3.3.0 patch3 3.3.0 patch4 3.3.0 patch5 3.3.0 patch6 3.3.0 patch7 3.4.0 - 3.4.0 patch1 3.4.0 patch2 3.4.0 patch3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | New CVE Received | [email protected] |