{"id":"CVE-2026-20305","title":"A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root","summary":"A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this v…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Cisco","product":"Cisco Identity Services Engine Software","affected":["identity_services_engine_software 3.1.0","identity_services_engine_software 3.1.0 p1","identity_services_engine_software 3.1.0 p3","identity_services_engine_software 3.1.0 p2","identity_services_engine_software 3.2.0","identity_services_engine_software 3.1.0 p4","identity_services_engine_software 3.1.0 p5","identity_services_engine_software 3.2.0 p1","identity_services_engine_software 3.1.0 p6","identity_services_engine_software 3.2.0 p2","identity_services_engine_software 3.1.0 p7","identity_services_engine_software 3.3.0","identity_services_engine_software 3.2.0 p3","identity_services_engine_software 3.2.0 p4","identity_services_engine_software 3.1.0 p8","identity_services_engine_software 3.2.0 p5","identity_services_engine_software 3.2.0 p6","identity_services_engine_software 3.1.0 p9","identity_services_engine_software 3.3 Patch 2","identity_services_engine_software 3.3 Patch 1","identity_services_engine_software 3.3 Patch 3","identity_services_engine_software 3.4.0","identity_services_engine_software 3.2.0 p7","identity_services_engine_software 3.3 Patch 4","identity_services_engine_software 3.4 Patch 1","identity_services_engine_software 3.1.0 p10","identity_services_engine_software 3.3 Patch 5","identity_services_engine_software 3.3 Patch 6","identity_services_engine_software 3.4 Patch 2","identity_services_engine_software 3.3 Patch 7","identity_services_engine_software 3.4 Patch 3","identity_services_engine_software 3.5.0","identity_services_engine_software 3.4 Patch 4","identity_services_engine_software 3.3 Patch 8","identity_services_engine_software 3.2 Patch 8","identity_services_engine_software 3.5 Patch 1","identity_services_engine_software 3.3 Patch 9","identity_services_engine_software 3.2 Patch 9","identity_services_engine_software 3.4 Patch 5","identity_services_engine_software 3.5 Patch 3","identity_services_engine_software 3.5 Patch 2","identity_services_engine_software 3.3 Patch 10","identity_services_engine_software 3.3 Patch 11","identity_services_engine_software 3.4 Patch 6","identity_services_engine_software 3.2 Patch 10","identity_services_engine_software 3.1.0 p72","identity_services_engine_software 3.1.0 p11","ise_passive_identity_connector 3.2.0","ise_passive_identity_connector 3.1.0","ise_passive_identity_connector 3.3.0"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T04:17:40.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20305","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ","label":"psirt@cisco.com"},{"url":"https://software.cisco.com"}],"tags":["nvd","cve.org","csaf","vendor-advisory","cisco"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-16T18:21:24.729728Z"},"ingestedAt":"2026-09-16T16:37:52.203Z","epss":0.01367,"epssPercentile":0.70214,"slug":"CVE-2026-20305","body":"## Overview\n\nA vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this vulnerability, the attacker must have valid administrative credentials.\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **cisco-sa-ise-cmd-inj-e2CuZCYZ** · Cisco · affected: Cisco ISE Passive Identity Connector (4 versions), Cisco Identity Services Engine Software (46 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ)","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}