VYPR
advisoryPublished Aug 13, 2026· 3 sources

Cisco ISE Vulnerability Allows Information Disclosure via Directory Traversal

A directory traversal vulnerability in Cisco Identity Services Engine (ISE) allows authenticated attackers to disclose sensitive information.

Cisco Identity Services Engine (ISE) is susceptible to a directory traversal vulnerability within its PatchUpdateListener component, according to an advisory from the Zero Day Initiative (ZDI).

This flaw, tracked as CVE-2026-20148, permits authenticated remote attackers to access and disclose sensitive information residing on vulnerable ISE installations. The vulnerability requires an attacker to possess valid credentials to be exploited.

The Zero Day Initiative has assigned a CVSS score of 4.9 to this vulnerability, categorizing it as medium severity. While not critical, the potential for information disclosure can still pose a significant risk to organizations relying on ISE for network access control and identity management.

Cisco ISE is a critical component for many enterprises, providing robust identity-based security services. It helps administrators control access to network resources based on user identity, device posture, and location. Exploiting this vulnerability could reveal configuration details, user data, or other sensitive operational information that could aid in further network reconnaissance or compromise.

Details regarding specific versions of Cisco ISE affected by this vulnerability have not been extensively detailed in the initial advisory, but users are strongly encouraged to consult Cisco's official security advisories for the most up-to-date information on affected products and patching status.

While the vulnerability requires authentication, the presence of valid credentials within an organization's network, either through compromised accounts or insider threats, could facilitate its exploitation. The disclosure of sensitive information could lead to a broader understanding of the network's security posture, potentially enabling attackers to identify other weaknesses or pivot to more critical systems.

Organizations utilizing Cisco ISE should prioritize reviewing their security configurations and ensure that only necessary personnel have authenticated access to the PatchUpdateListener component. Applying any available patches or workarounds provided by Cisco is crucial to mitigate the risk associated with this information disclosure vulnerability.

This vulnerability highlights the ongoing need for diligent security practices, including regular patching and access control management, even for components that require authentication for exploitation.

This new advisory from the Zero Day Initiative details CVE-2026-20190, a critical vulnerability in Cisco Identity Services Engine (ISE) that allows unauthenticated remote attackers to disclose sensitive information. The previous story mentioned a directory traversal vulnerability that required authentication, whereas this new flaw does not require any authentication to exploit and has a CVSS score of 7.5.

This new advisory (ZDI-26-579) details a remote code execution vulnerability (CVE-2026-20181) in Cisco Identity Services Engine, distinct from the information disclosure flaw previously reported. While the prior vulnerability allowed authenticated attackers to access sensitive data via directory traversal, this new finding enables authenticated remote attackers to execute arbitrary code on affected installations, carrying a CVSS score of 7.2.

Synthesized by Vypr AI