Authentication Bypass by Spoofing in Cisco Identity Services Engine (ISE) - CVE-2026-20071
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insufficient authentication checks that are performed while a user is being onboarded. A remote attacker on the local network can spoof the legitimate user and trigger a redirection to the guest web portal and gain access to the protected 802.1X network.