---
id: CVE-2026-20071
title: >-
  A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow
  of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the
  onboarding session of&nbsp;another user and access protected 802.1X networks
summary: >-
  A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow
  of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the
  onboarding session of&nbsp;another user and access protected 802.1X networks.
  &nbsp…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'
cwe:
  - CWE-290
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.1.0
  - identity_services_engine_software 3.1.0 p1
  - identity_services_engine_software 3.1.0 p3
  - identity_services_engine_software 3.1.0 p2
  - identity_services_engine_software 3.2.0
  - identity_services_engine_software 3.1.0 p4
  - identity_services_engine_software 3.1.0 p5
  - identity_services_engine_software 3.2.0 p1
  - identity_services_engine_software 3.1.0 p6
  - identity_services_engine_software 3.2.0 p2
  - identity_services_engine_software 3.1.0 p7
  - identity_services_engine_software 3.3.0
  - identity_services_engine_software 3.2.0 p3
  - identity_services_engine_software 3.2.0 p4
  - identity_services_engine_software 3.1.0 p8
  - identity_services_engine_software 3.2.0 p5
  - identity_services_engine_software 3.2.0 p6
  - identity_services_engine_software 3.1.0 p9
  - identity_services_engine_software 3.3 Patch 2
  - identity_services_engine_software 3.3 Patch 1
  - identity_services_engine_software 3.3 Patch 3
  - identity_services_engine_software 3.4.0
  - identity_services_engine_software 3.2.0 p7
  - identity_services_engine_software 3.3 Patch 4
  - identity_services_engine_software 3.4 Patch 1
  - identity_services_engine_software 3.1.0 p10
  - identity_services_engine_software 3.3 Patch 5
  - identity_services_engine_software 3.3 Patch 6
  - identity_services_engine_software 3.4 Patch 2
  - identity_services_engine_software 3.3 Patch 7
  - identity_services_engine_software 3.4 Patch 3
  - identity_services_engine_software 3.5.0
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.3 Patch 8
  - identity_services_engine_software 3.2 Patch 8
  - identity_services_engine_software 3.5 Patch 1
  - identity_services_engine_software 3.3 Patch 9
  - identity_services_engine_software 3.2 Patch 9
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.5 Patch 2
  - identity_services_engine_software 3.3 Patch 10
  - identity_services_engine_software 3.3 Patch 11
  - identity_services_engine_software 3.4 Patch 6
  - identity_services_engine_software 3.2 Patch 10
  - identity_services_engine_software 3.1.0 p72
  - identity_services_engine_software 3.1.0 p11
  - identity_services_engine_software 3.3 Patch 12
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:28:28.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20071'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
epss: 0.00146
epssPercentile: 0.04197
ingestedAt: '2026-09-16T16:37:52.178Z'
---

## Overview

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of&nbsp;another user and access protected 802.1X networks. &nbsp;

This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering&nbsp;a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ise-multi-vuln-kWLeNnRD** · Cisco · affected: Cisco Identity Services Engine Software (47 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD)
