CVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal a
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20146
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201460.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20146 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Cisco Identity Services
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilitiescisco-psirt · 2026-07-20
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund · 2026-07-16
- mediumCisco Identity Services Engine Path Traversal Vulnerabilitycisco-psirt · 2026-07-15
- criticalCisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilitiescisco-psirt · 2026-07-06
- unknownNCSC-2026-0208 [1.00] [M/H] Vulnerabilities fixed in Cisco Identity Services Enginencsc-nl · 2026-06-19
- mediumCisco Identity Services Engine Authentication Bypass Vulnerabilitiescisco-psirt · 2026-05-06
More from NVD Recent CVEs
- criticalCVE-2026-65321: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated at…2026-08-02
- lowCVE-2026-10774: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-ke…2026-08-02
- mediumCVE-2026-68583: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in t…2026-08-02
- mediumCVE-2026-68582: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vul…2026-08-02
- highCVE-2026-68581: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token managem…2026-08-02