CVE-2026-20285
Reported by cisco · Published September 16, 2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.1.0, 3.1.0 p1, 3.1.0 p3 |
| Cisco | Cisco ISE Passive Identity Connector | 3.2.0, 3.1.0, 3.3.0 |
| Cisco | Cisco ISE Passive Identity Connector | 3.2.0, 3.1.0, 3.3.0 |
| Cisco | Cisco Identity Services Engine Software | 3.1.0 p7, 3.3.0, 3.2.0 p3 |
Timeline
- Sep 16, 2026 Coalition ESS Score
- Sep 16, 2026 CVE Published
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 18, 2026 CVE Updated