CVE-2026-20147
CVE-2026-20186: A remote attacker with low privileges and without user interaction can inject commands to escalate privileges to root. If the ISE deployment is single-node, then that can cause Denial-of-Service (DoS). CVE-2026-20147: A remote attacker with low privileges and without user interaction can send crafted HTTP requests to execute arbitrary commands on the underlying operating system to elevate their privileges to root. If the ISE deployment is single-node, then that can cause Denial-of-Service (DoS). CVE-2026-20180: A remote attacker with low privileges and no user interaction can send crafted HTTP requests to execute code remotely because of insufficient validation of user-supplied input in HTTP request handling. That way they can raise their privileges to root and compromise the system.
EPSS 0.32% · 55.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Identity Services Engine (ISE) versions 3.x.x (3.1.0 - 3.4.0, and 3.1.0 p1-p10, 3.2.0 p1-p7, 3.3 Patches 1-7, and 3.4 Patches 1-3) |
Exploit Intelligence
- CIRCL seen: CVE-2026-20147 (circl-sighting)
- CIRCL seen: CVE-2026-20147 (circl-sighting)
- CIRCL seen: CVE-2026-20147 (circl-sighting)
- CIRCL seen: CVE-2026-20147 (circl-sighting)
- cisco-sa-ise-rce-traversal-8bYndVrZ (circl)
Timeline
- Apr 15, 2026 CVE Published
- Apr 15, 2026 PoC Published
- Apr 15, 2026 PoC Published
- Apr 15, 2026 PoC Published
- Apr 15, 2026 PoC Published
- Apr 16, 2026 Security Advisory
- Apr 16, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-cisco-ise-can-lead-rce-patch-immediately advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv vendor
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ vendor
- https://github.com/advisories/GHSA-4w7q-f6rr-2p4r technical
- https://github.com/advisories/GHSA-6m6h-8f8v-r7j4 technical
- https://github.com/advisories/GHSA-6fqc-22r3-wrxm technical