Click Icon to Copy Verbose Score
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:X
-
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it is easy to get to root from the achieved privilege level.
Cisco has released software updates that address these vulnerabilities. There are workarounds that address one of these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCcThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.
-
Vulnerable Products
CVE-2026-20284: This vulnerability affects Cisco ISE if the SXP service is enabled and at least one SXP connection is configured.
CVE-2026-20283: This vulnerability affects Cisco ISE if there is more than one network interface and at least one of them is configured as an active IPsec tunnel between Cisco ISE and a physical Network Access Device (NAD).
CVE-2026-20282: This vulnerability affects Cisco ISE, regardless of device configuration.
For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.
Determine the SXP Configuration
To determine whether the SXP service is enabled, do the following:
- Choose Administration > System > Deployment > Deployment.
- Click the node to check.
- From the Policy Service section, look at the Enable SXP Service setting.
If the service is enabled, the node has a vulnerable configuration.
Note: Each node must be checked.
To determine whether an SXP connection is configured, check for devices by choosing Work Centers > TrustSec > SXP > SXP Devices.
- If devices are listed, the node has a vulnerable configuration.
- If no devices are listed, the node does not have a vulnerable configuration.
Determine the IPsec Tunnel Configuration
To determine whether an IPsec tunnel is configured, check for entries by choosing Administration > System > Settings > Protocols > IPsec > Native IPsec.
If there are no entries, the device does not have a vulnerable configuration.
If there are entries, review the NAD IP address.
- If only an IP address or fully qualified domain name (FQDN) is configured, the device does not have a vulnerable configuration.
- If anything else is present in the field, the device has a vulnerable configuration.
If the Configure VTI box is checked, review the Remote and Local Tunnel IP address.
- If only an IP address or FQDN is configured, the device does not have a vulnerable configuration.
- If anything else is present in the field, the device has a vulnerable configuration.
Products Confirmed Not Vulnerable
Only products listed in the Vulnerable Products section of this advisory are known to be affected by these vulnerabilities.
Cisco has confirmed that these vulnerabilities do not affect Cisco ISE Passive Identity Connector (ISE-PIC).
-
The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.
Details about the vulnerabilities are as follows:
CVE-2026-20284: Cisco ISE SXP REST API SQL Injection Vulnerability
A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks.
This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Bug ID(s): CSCwu66592
CVE ID: CVE-2026-20284
Security Impact Rating (SIR): Critical
CVSS Base Score: 9.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCVE-2026-20283: Cisco ISE IPsec Open API Command Injection Vulnerability
A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.
This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.
To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel.
Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
Bug ID(s): CSCwu31070
CVE ID: CVE-2026-20283
Security Impact Rating (SIR): High
CVSS Base Score: 6.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NCVE-2026-20282: Cisco ISE Authenticated Write Vulnerability
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system.
To exploit this vulnerability, the attacker must have valid administrative credentials.
Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Bug ID(s): CSCwu40000
CVE ID: CVE-2026-20282
Security Impact Rating (SIR): High
CVSS Base Score: 4.9
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
-
CVE-2026-20282 and CVE-2026-20284: There are no workarounds that address these vulnerabilities.
CVE-2026-20283: There is a workaround that addresses this vulnerability. The vulnerability is present only when an IPsec VTI tunnel is created using the API. However, using the Cisco ISE web interface to create an IPsec VTI tunnel does not allow the vulnerability to be configured.
If a vulnerable configuration is present, do the following:
- Return to Administration > System > Settings > Protocols > IPsec > Native IPsec.
- Choose the tunnel with the vulnerable configuration and remove it.
- Add the tunnel back using the web interface.
While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.
-
Cisco considers any workarounds and mitigations (if applicable) to be temporary solutions until an upgrade to a fixed software release is available. To remediate these vulnerabilities and avoid future exposure as described in this advisory, Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.
Fixed Releases
In the following table, the left column lists Cisco software releases. The remaining columns indicate whether a release is affected by the vulnerabilities that are described in this advisory and the first release that includes the fix for these vulnerabilities. Customers are advised to upgrade to an appropriate fixed software release as indicated in this section.
Cisco ISE Release First Fixed Release
for CVE-2026-20284First Fixed Release
for CVE-2026-20283First Fixed Release
for CVE-2026-202823.1 and earlier 3.1 Patch 12 Not vulnerable. Migrate to a fixed release. 3.2 3.2 Patch 11 Not vulnerable. Migrate to a fixed release. 3.3 3.3 Patch 12 3.3 Patch 12 3.3 Patch 12 3.4 3.4 Patch 7 3.4 Patch 7 3.4 Patch 7 3.5 3.5 Patch 4 3.5 Patch 4 3.5 Patch 4 For instructions on upgrading a device, see the Upgrade Guides on the Cisco Identity Service Engine support page.
The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed release information that is documented in this advisory.
-
The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory.
The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.
-
Cisco would like to thank Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd for reporting these vulnerabilities.
-
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
For additional information on Cisco's vulnerability management, disclosure cadence, and software patching strategy, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model.
-
Show LessVersion Description Section Status Date 1.0 Initial public release. — Final 2026-SEP-16
-
SOFTWARE DOWNLOADS AND TECHNICAL SUPPORT
The Cisco Support and Downloads page on Cisco.com provides information about licensing and downloads. This page can also display customer device support coverage for customers who use the My Devices tool. Please note that customers may download only software that was procured from Cisco directly or through a Cisco authorized reseller or partner and for which the license is still valid.
Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC). Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.
When considering software upgrades, customers are advised to regularly consult the advisories for the relevant Cisco products to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.
LEGAL DISCLAIMER DETAILS
CISCO DOES NOT MAKE ANY EXPRESS OR IMPLIED GUARANTEES OR WARRANTIES OF ANY KIND, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING, CISCO DOES NOT GUARANTEE THE ACCURACY OR COMPLETENESS OF THIS INFORMATION. THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
Copies or summaries of the information contained in this Security Advisory may lack important information or contain factual errors. Customers are advised to visit the Cisco Security Advisories page for the most recent version of this Security Advisory. The Cisco Product Security Incident Response Team (PSIRT) assesses only the affected and fixed release information that is documented in this advisory. See the Cisco Security Vulnerability Policy for more information.