Skip to content
CiscoCVE-2026-20146

Cisco ISE Passive Identity Connector: path traversal

Medium5.5CVE-2026-20146 · Published Jul 15, 2026 · updated Sep 25, 2026

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco ISE Passive Identity Connector
Product
<= 3.2.0No fix yet
<= 3.1.0No fix yet
<= 3.3.0No fix yet
<= 3.4.0No fix yet
Cisco Identity Services Engine Software
Product
<= 3.1.0No fix yet
<= 3.1.0 p1No fix yet
<= 3.1.0 p3No fix yet
<= 3.1.0 p2No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco RoomOS Software: improper access control
High8.8Jul 15
Cisco RoomOS Software: improper input validation
High7.5Jul 15
Cisco RoomOS Software: memory corruption
High8.1Jul 15
Cisco RoomOS Software: missing encryption
High7.5Jul 15
As part of Cisco's ongoing commitment to proactive security and product quality
High7.5Jul 15
Cisco RoomOS Software: unhandled exceptional condition
High7.5Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.