Cisco Identity Services Engine Path Traversal Vulnerability
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y Security Impact Rating: Medium CVE: CVE-2026-20146
CSIRTS triage
- What
- A vulnerability allows an authenticated remote attacker to perform path traversal attacks.
- Who is affected
- Authenticated users of Cisco Identity Services Engine and ISE Passive Identity Connector.
- Urgency
- Remediation is medium urgency as it requires valid administrative credentials to exploit.
- Action
- Update to the latest software version from Cisco.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Identity Services Engine
Get an email when a new Identity Services Engine advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201460.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20146 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund
- mediumCVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connect…nvd
- highCisco Advance Notification for Publication of July 15, 2026, Security Advisoriescisco-psirt
Recent advisories for Cisco Identity Services
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilitiescisco-psirt · 2026-07-20
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund · 2026-07-16
- mediumCVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connect…nvd · 2026-07-15
- criticalCisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilitiescisco-psirt · 2026-07-06
- unknownNCSC-2026-0208 [1.00] [M/H] Vulnerabilities fixed in Cisco Identity Services Enginencsc-nl · 2026-06-19
- mediumCisco Identity Services Engine Authentication Bypass Vulnerabilitiescisco-psirt · 2026-05-06
More from Cisco Security Advisories
- highCisco Secure Firewall Management Center Software Static Credential Vulnerability2026-07-31
- criticalCisco Secure Firewall Management Center Software Authentication Bypass Vulnerability2026-07-31
- unknownCisco Advance Notification for Publication of August 5, 2026, Security Advisories2026-07-29
- unknownCisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privile…2026-07-21
- mediumCisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities2026-07-20