VYPR
Medium severity4.9NVD Advisory· Published Apr 15, 2026· Updated Jul 8, 2026

CVE-2026-20148

CVE-2026-20148

Description

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

86
  • cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*+ 41 more
    • cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*range: <3.1
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch10:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*
  • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*+ 41 more
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*range: <3.1.0
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch10:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.1.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.2.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch2:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

1