OVERVIEW: CVE-2026-20147 is a command injection vulnerability affecting Cisco ISE and Cisco ISE-PIC that allows authenticated remote attackers to execute arbitrary commands on affected devices through insufficient input validation. The vulnerability can be exploited by sending a crafted HTTP request to a vulnerable device, requiring valid administrative credentials. SEVERITY: This vulnerability carries a CRITICAL CVSS 3.1 rating of 9.9 with a network-based attack vector, low complexity, and low privilege requirements. Successful exploitation grants user-level access with potential privilege escalation to root, enabling complete system compromise. In single-node ISE deployments, exploitation could cause denial of service conditions that prevent unauthenticated endpoints from accessing the network until service restoration. EXPLOITATION STATUS: The vulnerability currently shows no evidence of active exploitation in the wild, with an EPSS score of 0.0028 indicating minimal real-world exploit probability. It is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. However, the high CVSS rating and administrative credential requirement warrant prompt patching to prevent potential future exploitation by insider threats or attackers with compromised administrative accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:-:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch1:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch10:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.