Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root . This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit could allow the attacker to elevate their privileges to root on the underlying operating system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB Security Impact Rating: Medium CVE: CVE-2026-20136
CSIRTS triage
- What
- A vulnerability could allow an authenticated, local attacker to perform a command injection attack and elevate privileges.
- Who is affected
- Authenticated local users with administrative privileges on affected devices.
- Urgency
- Remediation is necessary due to the potential for privilege escalation.
- Action
- Update to the latest software version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Identity Services Engine
Get an email when a new Identity Services Engine advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201360.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20136 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Cisco Identity Services
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilitiescisco-psirt · 2026-07-20
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund · 2026-07-16
- mediumCVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connect…nvd · 2026-07-15
- mediumCisco Identity Services Engine Path Traversal Vulnerabilitycisco-psirt · 2026-07-15
- criticalCisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilitiescisco-psirt · 2026-07-06
- unknownNCSC-2026-0208 [1.00] [M/H] Vulnerabilities fixed in Cisco Identity Services Enginencsc-nl · 2026-06-19
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19