Cisco Identity Services Engine Command Injection Vulnerability Allowing Privilege Escalation to Root

Vulnerability

A command injection vulnerability has been identified in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows an authenticated, local attacker with administrative privileges to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized privilege escalation to root. The issue arises from inadequate validation of user-supplied input, enabling attackers to exploit the vulnerability by crafting specific input for a CLI command.

Impact

Exploitation of this vulnerability could result in unauthorized command execution on the operating system, with elevated privileges to root.

Remediation

Cisco has released patches for this vulnerability. Affected users should upgrade to Cisco ISE or ISE-PIC version 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3. For instructions on upgrading, refer to the Cisco Identity Service Engine upgrade guides.

Added: Apr 15, 2026, 5:52 PM
Updated: Apr 15, 2026, 5:52 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
3.0
remediation
0.0
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.