Input validation error in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20181
Published: June 17, 2026
Cisco Identity Services Engine (ISE)
ISE Passive Identity Connector (ISE-PIC)
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in HTTP request handling when processing user-supplied input. A remote privileged user can send a crafted HTTP request to execute arbitrary code.
Successful exploitation could provide user-level access to the underlying operating system and allow further privilege escalation to root. In single-node deployments, exploitation could cause the affected node to become unavailable.
How to mitigate CVE-2026-20181
Install security update from vendor's website.
Note, release 3.5 Patch 4 will be available in August 2026.