cbcvebase.
CVE-2026-20029
published 2026-01-07

CVE-2026-20029: A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an…

PriorityP277medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
5.64%
92.0th percentile
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a malicious XML file uploaded via the web-based management interface of Cisco ISE / ISE-PIC; monitor for suspicious file uploads to the ISE admin interface, particularly XML files targeting the licensing feature
  • The vulnerability class is XML External Entity (XXE) injection in the licensing component; detection rules should look for XXE payloads (e.g., DOCTYPE/ENTITY declarations referencing local file paths) in XML uploaded to Cisco ISE
  • A public proof-of-concept exploit is available; prioritize detection and patching for ISE versions earlier than 3.2, 3.2 (pre-Patch 8), 3.3 (pre-Patch 8), and 3.4 (pre-Patch 4)
  • Successful exploitation allows reading arbitrary files from the underlying OS; monitor ISE logs for unexpected file-read activity or anomalous responses from the management interface containing OS-level file content
  • ·Exploitation requires valid administrative credentials; scope detection and response to authenticated admin sessions performing unusual file uploads to the ISE web management interface

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vulncheck4.9MEDIUM
vendor_cisco4.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.