
[CIVN-2026-0462] Multiple Vulnerabilities in Cisco Identity Services Engine
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Cisco Identity Services Engine
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Systems Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Overview
Multiple vulnerabilities have been reported across various components of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) which could allow remote attackers to bypass authentication entirely, execute arbitrary code or commands as the root user, conduct SQL injection attacks, perform XML External Entity (XXE) injections, and gain full write access to the underlying operating system.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating this software.
Description
1. Authentication Bypass Vulnerability ( CVE-2026-76460 )
This vulnerability exists due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint.
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
2. Command Injection Vulnerability ( CVE-2026-20305 CVE-2026-20306 )
These vulnerabilities exist due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
3. SQL Injection Vulnerability ( CVE-2026-20284 )
This vulnerability exists due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device.
Successful exploitation of this vulnerability could allow the attacker to view or modify data on the underlying database for the affected device.
4. Command Injection Vulnerability ( CVE-2026-20283 )
This vulnerability exists due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending a crafted input to the IPsec Open API endpoint on an affected device.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands on the underlying operating system.
5. Authenticated Write Vulnerability ( CVE-2026-20282 )
This vulnerability exists due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by a crafted HTTP request to an affected device.
Successful exploitation of this vulnerability could allow the attacker to obtain write access to the underlying operating system.
6. Remote Code Execution Vulnerability ( CVE-2026-76176 CVE-2026-20211 CVE-2026-20307 )
These vulnerabilities exist due to insecure deserialization of a user-supplied Java byte stream or insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted serialized Java object to the web-based management interface of an affected device and HTTP request to an affected device.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code on the device, obtain system-level access to the underlying operating system, user-level access to the underlying operating system and elevate privileges to root
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
CVE Name
CVE-2026-76460
CVE-2026-20305
CVE-2026-20306
CVE-2026-20284
CVE-2026-20283
CVE-2026-20282
CVE-2026-76176
CVE-2026-20211
CVE-2026-20307
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtQCYACgkQ3jCgcSdc
ys9ChQ//W3GTtLEj6mlqyBZ91oB0LeCUKksfRl5w2YrKUgmfLG2dhrelJywFS1NH
xHzJNFmGyDgU5t97L9Gev6GHZtAVrdhv9kajUH1YC+XOZhedNzWsrhFcVSpvQCbf
YO7pDjjpJ32c2fg4JC2OAB0AcxOzb8A+he1QmHaGgO8Kq6qlWyvHNILq9FvsUlAP
j4jOI9q6yapXKhuN/Dl/1V7NW8dEx3yDPCB4IzZyPWGRrc7/3kFfpmRS1t+NzKCA
/Q9+pTe3NUM8DxGymSKn8/AqHpqJ/z1Vkmem6pmAFa9qH8e6OeGxTkn1PxGPXR4q
R+7/Gh5L6zkuXnQ5EPEZb/VxEhbPzeACm9ccBtjSHjOfgqAPH1zsvhxxJ6p+k9+b
28d8Jwa+Ptra/8ijVNvnzazZ/CvXnSkpSOMj/XYLVhITgvAI4Zxl7v8KA4nWaDyh
BjVHYOm6FV4HRxdlS2jDw2wxTYhdjEE1C790lMPH8/avRi/gAZ0foh9cJvFy/FiG
3XLgX1LvYOsPqH2hsty7X3gFcKNs4giYzPtuEjhkyYxZWPELvF/2X2Y2Nxo5irxM
KXOsRK8fPWCo1NDcdx6LuEB8G+GOZRO+7yctZnpSFkSKw9jalUseJO2hPJFX2/G3
oY/GWADN2XQ4Z1pDO5TWzfcOMk66WRKMk1PQFUw0HCUJWCiWgjs=
=jSDC
—–END PGP SIGNATURE—–


