Skip to content

CVE-2026-20306 CVE-2026-20305

Cisco Identity Services Engine command injection allows authenticated attackers to gain root (CVE-2026-20305, CVE-2026-20306)

Critical 9.1 Vendor: Cisco Published

Two critical command injection flaws in Cisco Identity Services Engine and ISE-PIC allow an authenticated administrator to execute code as root. In single-node ISE deployments, an exploited node can become unavailable and block new network access. Cisco has released fixes; no workaround exists.

What happened

Two command injection vulnerabilities have been published for Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). CVE-2026-20306 is in the REST API; CVE-2026-20305 is in the diagnostic tools. Both can be reached over the network by a remote attacker, but the attacker must hold valid administrative credentials. No user interaction is required.

The vulnerabilities are caused by improper validation of user-supplied input. By sending crafted commands to the web-based management interface, an attacker could execute arbitrary code on the underlying operating system and elevate privileges to root. In single-node ISE deployments, successful exploitation could also make the affected node unavailable, blocking network access for endpoints that have not already authenticated until the node is restored.

Cisco's Product Security Incident Response Team states that it is not aware of any public announcements or malicious use of these vulnerabilities.

Who is affected

Cisco Identity Services Engine Software is affected. For CVE-2026-20306: 3.4 Patch 4, 3.4 Patch 5, 3.4 Patch 6 and 3.5 Patch 3. For CVE-2026-20305: 3.1.0, 3.1.0 p1, 3.1.0 p2, 3.1.0 p3, 3.1.0 p4, 3.1.0 p5, 3.2.0 and 3.2.0 p1.

Cisco ISE Passive Identity Connector is affected. For CVE-2026-20306: 3.4.0. For CVE-2026-20305: 3.1.0, 3.2.0, 3.3.0 and 3.4.0.

These products provide identity and network access control services. A compromised or unavailable node can affect network access decisions.

What to do now

Cisco has released fixes for these vulnerabilities, but the specific fixed build numbers are not listed in this summary. Use the Cisco advisory to confirm the correct release for your version train.

  1. Identify your Cisco ISE and ISE-PIC deployments and check them against the affected versions above.
  2. Apply the fixed software for your release. There are no workarounds for these vulnerabilities.
  3. Until patching is complete, restrict access to the management interface to trusted administrative networks.
  4. Review administrative sessions for unexpected command activity or configuration changes.

How to detect it

Exploitation is carried out through the web-based management interface using administrative credentials. Review administrative session logs and management-interface configuration changes for unexpected commands. In single-node ISE deployments, unplanned node unavailability that persists until restoration may indicate exploitation.

Beyond the patch

Command injection in a management interface is the kind of issue that authenticated testing and hardening should find before an attacker can abuse it; Implementation & Assessment Services covers penetration testing and configuration review for Cisco estates. Once administrative access is abused, the resulting code execution and privilege escalation leaves signals that Managed Detection & Response (MDR) watches for across EDR and SIEM. Patch first, then close that gap.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20306
Cisco Identity Services Engine Software
3.4 Patch 4
3.4 Patch 5
3.5 Patch 3
3.4 Patch 6
No fixed version listed yet
CVE-2026-20306
Cisco ISE Passive Identity Connector
3.4.0No fixed version listed yet
CVE-2026-20305
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20305
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.