Improper Authorization in Cisco Identity Services Engine (ISE) - CVE-2026-20286
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to modify descriptions of files on specific pages.
The vulnerability exists due to improper authorization in the web-based management interface when processing crafted HTTP requests. A remote user can submit a crafted HTTP request to modify descriptions of files on specific pages.
Valid administrator credentials are required.