OS Command Injection in Cisco Identity Services Engine (ISE) - CVE-2026-20305
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code as the root user.
The vulnerability exists due to improper validation of user-supplied input in the diagnostic tools of Cisco ISE and ISE-PIC when handling crafted commands sent to the web-based management interface. A remote privileged user can send crafted commands to the web-based management interface to execute arbitrary code as the root user.