Cisco ISE Passive Identity Connector: path traversal
Medium5.5CVE-2026-20146 · Published Jul 15, 2026 · updated Sep 25, 2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco ISE Passive Identity Connector Product | <= 3.2.0 | No fix yet |
| <= 3.1.0 | No fix yet | |
| <= 3.3.0 | No fix yet | |
| <= 3.4.0 | No fix yet | |
| Cisco Identity Services Engine Software Product | <= 3.1.0 | No fix yet |
| <= 3.1.0 p1 | No fix yet | |
| <= 3.1.0 p3 | No fix yet | |
| <= 3.1.0 p2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 15 | Cisco RoomOS Software: improper access control | High8.8 | No fix yet |
| Jul 15 | Cisco RoomOS Software: improper input validation | High7.5 | No fix yet |
| Jul 15 | Cisco RoomOS Software: memory corruption | High8.1 | No fix yet |
| Jul 15 | Cisco RoomOS Software: missing encryption | High7.5 | No fix yet |
| Jul 15 | As part of Cisco's ongoing commitment to proactive security and product quality | High7.5 | No fix yet |
| Jul 15 | Cisco RoomOS Software: unhandled exceptional condition | High7.5 | No fix yet |