CVE-2026-20285: Cisco Identity Services Engine Software
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials.
Affected products
- Cisco Cisco Identity Services Engine Software: version 3.1.0 only; version 3.1.0 p1 only; version 3.1.0 p3 only; version 3.1.0 p2 only; version 3.2.0 only; version 3.1.0 p4 only; …
- Cisco Cisco Ise Passive Identity Connector: version 3.2.0 only; version 3.1.0 only; version 3.3.0 only; version 3.4.0 only; version 3.5.0 only
Published 2026-09-16. Last modified 2026-09-18.