CVE-2026-20148
published 2026-04-15CVE-2026-20148: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating…
PriorityP343medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
6.92%
93.4th percentile
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.
Affected
127 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Identity Services Engine Software HTTP path traversal (cisco-sa-ise-rce-traversal-8bYndVrZ / EUVD-2026-22963)
vuldb·2026-04-15·CVSS 4.9
CVE-2026-20148 [MEDIUM] Cisco Identity Services Engine Software HTTP path traversal (cisco-sa-ise-rce-traversal-8bYndVrZ / EUVD-2026-22963)
A vulnerability, which was classified as critical, has been found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. Affected by this issue is some unknown functionality of the component HTTP Handler. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-20148. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-m2rm-r929-jjfm: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying opera
ghsa_unreviewed·2026-04-15
CVE-2026-20148 [MEDIUM] CWE-22 GHSA-m2rm-r929-jjfm: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying opera
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.
Cisco
Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20148 Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
CVE-2026-20148: Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to achieve remote code execution or conduct path traversal attacks on an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-22, CWE-77, CWE-22, CWE-77
Bug IDs: CSCws52717, CSCws52738, CSCws52738, CSCws52717
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published