---
id: CVE-2026-20306
title: >-
  A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an
  authenticated, remote attacker to perform command injection attacks on the
  underlying operating system and elevate privileges to root
summary: >-
  A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an
  authenticated, remote attacker to perform command injection attacks on the
  underlying operating system and elevate privileges to root. To exploit this
  vulnerability,…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.4 Patch 6
  - ise_passive_identity_connector 3.4.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T04:17:40.777'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20306'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T17:16:03.380469Z'
ingestedAt: '2026-09-16T16:37:52.204Z'
epss: 0.01367
epssPercentile: 0.70643
---

## Overview

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ise-cmd-inj-e2CuZCYZ** · Cisco · affected: Cisco Identity Services Engine Software (4 versions), Cisco ISE Passive Identity Connector 3.4.0 · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ)
