[CIVN-2026-0049] Vulnerability in Cisco Identity Services Engine (ISE)

By Published On: January 28, 2026

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Vulnerability in Cisco Identity Services Engine (ISE) 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Systems Affected
Cisco ISE
Overview
A vulnerability has been reported in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an  authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
Target Audience: 
All IT administrators and individuals responsible for maintaining and updating in Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to the insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-9TDh2kx
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-9TDh2kx
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-9TDh2kx
CVE Name
CVE-2026-20076
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAml6Je0ACgkQ3jCgcSdc
ys89nQ//bj3zGhuNH9BAsHxWUt80FPFLBDML8q/5GktxttbKlaDn1iPdJtfb8G2f
3/31VLCz6AU6y9JirUNNk8xYPiUqVmmJ5LjvtvhCYxW9c1jZXYTjHAmxHgw1F5di
d0PFaa2GskH1Ickf4GBohh/AAd8JNJBz3J51hoJaN+gmP18M+4zDrcUE/5osHqE9
k6V4/wCNPr8iN6RnF2WBjeomdRPTioRcXaiwNuC7gpq4RqkdlOjOqwjUDDJMjG9E
e1sfoJEYqlZ+VAJcsUZQ0qdGUbuxAqL9eh+3y043pt7yKfmTHTahKZvrGZH441jQ
RQeNRWiGtLzugn6gY0ed3p8nywwMG3k5BIVME2fqbqFDhcU7eYod2KHRDK1pcE8t
EU4pRKQIyWYFlirMEfustMzP1BPVFKocEUpiKcGh8qhyXjuNv2Wjo9hMJHbP6hey
+1tLdgiV9NT898Oc4HA6OOlpMomHR4A1ZtpyEte2PZbzOyUGfbzQIlgkw2DSxUlt
Ubn2a6CocTRC29p7AN+Yin9XVI/NochJJfe52fiNJKD4lZ9kHt9Kv6VGWoHhpNOm
jP/4ZrLLUkaSSLS5F0clVezPKxYRVlJbjIFBNs/8YXgAoH/DSbnsKaHUWnd4rgFH
MxasnAb/KchqH2/IHJZqjg83d24HRgmhNKCd7+BBE2H2Fi3tF08=
=i9gi
—–END PGP SIGNATURE—–

Share this article