Cisco Identity Services Engine Vulnerable to Remote Code Execution
A critical command injection vulnerability in Cisco Identity Services Engine allows authenticated attackers to achieve remote code execution.

A critical vulnerability affecting Cisco Identity Services Engine (ISE) has been disclosed, enabling authenticated attackers to execute arbitrary code on vulnerable systems. The flaw, identified as ZDI-26-716 and assigned CVE-2026-20176, carries a CVSS score of 7.2, underscoring its significant security implications.
The vulnerability resides within the createDBLink method of the Cisco ISE software. It stems from a failure to properly validate user-supplied input before it is used in a system command. This oversight allows a malicious actor, who has already gained authenticated access to the system, to inject and execute arbitrary commands, effectively compromising the affected appliance.
Successful exploitation of this vulnerability would allow an attacker to run commands with the privileges of the iseadminportal user. This level of access could enable attackers to further escalate their privileges, exfiltrate sensitive data, or deploy additional malicious payloads on the compromised network infrastructure.
Cisco has acknowledged the vulnerability and has released security updates to address the issue. Organizations utilizing Cisco ISE are strongly advised to apply these patches as soon as possible to mitigate the risk of exploitation. Further details on the remediation can be found in Cisco's official security advisory.
The Zero Day Initiative (ZDI) was responsible for the coordinated disclosure of this vulnerability. The advisory was publicly released on September 18, 2026, following the vendor's confirmation and the release of a fix. The vulnerability was initially reported to Cisco on May 20, 2026, allowing a reasonable window for remediation.
This discovery highlights the ongoing need for robust security practices, especially for network access control solutions like Cisco ISE, which often sit at the heart of an organization's security posture. The requirement for authentication before exploitation means that attackers would likely target compromised credentials or leverage other vulnerabilities to gain initial access before exploiting this specific flaw.
Jonathan Lein of TrendAI Research is credited with discovering and reporting this vulnerability. The disclosure timeline emphasizes the importance of timely patching and the collaborative efforts between security researchers and vendors in securing complex enterprise software.