CVE-2026-20136Improper Encoding or Escaping of Output in Cisco Identity Services Engine Software

Severity
6.0MEDIUMNVD
EPSS
0.1%
top 84.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15

Description

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit cou

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 0.8 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

3
VulDB
Cisco Identity Services Engine Software up to 3.5.0 CLI command injection (cisco-sa-ise-cmd-inj-5WSJcYJB / EUVD-2026-22960)2026-04-15
GHSA
GHSA-hj84-36vf-hc6f: A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, lo2026-04-15
CVEList
Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability2026-04-15
CVE-2026-20136 — Cisco vulnerability | cvebase