MEDIUM

CVE-2026-20146

Cisco Identity Services Engine Passive Identity Connector 2026-07-15 CVSS v3.1
CVSS
5.5

Description

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. 

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

Summary dbcve.org

This is a path traversal vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). An authenticated attacker with administrative credentials can exploit improper validation of user-supplied input in HTTP requests to read or delete arbitrary files on the underlying operating system.

Mitigation

Apply the relevant Cisco security patch or upgrade to a fixed version as specified in Cisco's official security advisory for CVE-2026-20146. Restrict administrative access to trusted personnel and monitor for suspicious file access patterns.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

0.5%
Probability of exploitation in next 30 days
41.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE