Cisco Security Advisory
Follow
Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities
Multiple vulnerabilities have been identified in Cisco Identity Services Engine (ISE). These vulnerabilities could allow an authenticated, remote attacker to perform SQL injections. Attackers could also modify data on affected devices through these vulnerabilities. Furthermore, arbitrary commands could be executed on the underlying operating system. Cisco has assigned a Security Impact Rating of Critical to the overall set of vulnerabilities. Specifically, CVE-2026-20282 and CVE-2026-20283 are rated High due to the ease of achieving root privilege from the exploited level. Cisco has released software updates to fix these vulnerabilities. Workarounds are available for one of the identified vulnerabilities. The advisory provides further details on these security issues. A complete list of related advisories and documentation on ISE security hardening is also available.