CVE-2026-20146
MEDIUMCisco Identity Services Engine Path Traversal Vulnerability
Title source: cnaDescription
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
References (1)
Core 1
Core References
cisco-sa-ise-traversal-xNt7wb2Y
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y
Scores
CVSS v3
5.5
EPSS
0.0034
EPSS Percentile
26.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (48)
Cisco/Cisco Identity Services Engine Software
3.1.0
Cisco/Cisco Identity Services Engine Software
3.1.0 p1
Cisco/Cisco Identity Services Engine Software
3.1.0 p10
Cisco/Cisco Identity Services Engine Software
3.1.0 p2
Cisco/Cisco Identity Services Engine Software
3.1.0 p3
Cisco/Cisco Identity Services Engine Software
3.1.0 p4
Cisco/Cisco Identity Services Engine Software
3.1.0 p5
Cisco/Cisco Identity Services Engine Software
3.1.0 p6
Cisco/Cisco Identity Services Engine Software
3.1.0 p7
Cisco/Cisco Identity Services Engine Software
3.1.0 p8
... and 38 more
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026