CISCO Security Advisory

Published Date: July 15, 2026

CVE: CVE-2026-20146

Advisory Summary

Cisco has revealed a medium-severity security flaw (CVE-2026-20146) affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). This vulnerability allows an authenticated remote attacker—who possesses valid administrative credentials—to exploit path traversal weaknesses. By sending a specially crafted HTTP request, the attacker can read or delete arbitrary files on the underlying operating system.

The root cause lies in insufficient validation of user-supplied input, making these critical infrastructure components vulnerable to file system manipulation. This can expose sensitive information or disrupt system operations by unauthorized file deletions.

Cisco is in the process of releasing software patches that will mitigate this vulnerability. Currently, no alternative workarounds exist, so prompt application of these updates is essential for organizations leveraging Cisco ISE and ISE-PIC environments to safeguard their systems against potential exploits.

🔐 Security professionals managing Cisco ISE deployments are strongly advised to monitor Cisco’s updates and apply patches as soon as they become available to maintain secure and resilient network access control infrastructure.

-2026-20146

Reference: Vendor Advisory