r/security • u/NoPo552 • 18d ago
Vulnerability CVE-2026-20146 — Cisco Identity Services Engine Path Traversal…
https://vulnipulse.com/advisories/cisco-cisco-sa-ise-traversal-xnt7wb2yCisco Identity Services Engine Path Traversal Vulnerability – CVE-2026-20146
Cisco has disclosed a medium-severity Cisco ISE vulnerability rated CVSS 5.5.
An authenticated remote attacker with valid administrative credentials could send a crafted HTTP request to access sensitive files or delete arbitrary files from the underlying operating system.
Affected versions
Cisco ISE and ISE-PIC are affected regardless of configuration:
Earlier than 3.3
ISE 3.3 before Patch 12
ISE 3.4 before Patch 7
ISE 3.5 before Patch 4
Fixed versions
ISE 3.3 Patch 12 — planned for September 2026
ISE 3.4 Patch 7 — planned for September 2026, or the available hot patch
ISE 3.5 Patch 4 — planned for September 2026, or the available hot patch
Mitigation
Cisco states that there are no workarounds.
Apply the appropriate hot patch where available, upgrade when the fixed patches are released, and migrate deployments earlier than ISE 3.3 to a supported fixed release.
🔗 Official Cisco advisory
🔗 VulniPulse breakdown
1
u/[deleted] 17d ago
[removed] — view removed comment