CVE-2026-20180 is a critical remote code execution vulnerability in Cisco Identity Services Engine (ISE) that allows authenticated attackers with Read Only Admin credentials or higher to execute arbitrary operating system commands through insufficient input validation in HTTP requests. The vulnerability enables attackers to gain user-level access to the underlying OS and escalate privileges to root, with potential impacts including complete system compromise and denial of service in single-node deployments that could disconnect unauthenticated endpoints from the network. The vulnerability carries a CVSS 3.1 score of 9.9 (Critical) with a network-based attack vector, low attack complexity, and low privilege requirements, resulting in high confidentiality, integrity, and availability impacts across system boundaries. Exploitation requires only crafted HTTP requests and an attacker with minimal authentication credentials, making it relatively straightforward to exploit from a technical standpoint. This vulnerability is not currently listed on the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. The EPSS score of 0.0026 indicates this CVE is in the lower percentile for real-world exploitation probability, and the vulnerability remains on inactive status from a community attention standpoint. However, the critical CVSS rating and authentication-only barrier to exploitation warrant prompt patching to mitigate potential future exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.