A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, rem…

cve CVE-2026-20146 1 source, 1 claim · Watch

NVD writes:
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitiv… the claim
Severity
MEDIUM NVD
CVSS
5.5 NVD
Vendor
Cisco NVD
Product
Cisco Identity Services Engine Software NVD
CWE
CWE-22 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-07-15first spoke of it: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.NVD

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

What it is to other things

affectscisco/identity_services_engine
NVD
affectscisco/identity_services_engine_passive_identity_connector
NVD
made_bycisco
NVD

In words only, so not counted until a person confirms one:

affectscisco/cisco_identity_services_engine_software
NVD says “Cisco · Cisco Identity Services Engine Software”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.5
receipt
Source
NVD
Its words
5.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-22
receipt
Source
NVD
Its words
CWE-22
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-22
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDCisco Identity Services Engine Software
receipt
Source
NVD
Its words
Cisco Identity Services Engine Software
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco Identity Services Engine Software
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDCisco
receipt
Source
NVD
Its words
Cisco
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p9"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p7"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p10"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 6"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 7"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 4"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 8"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 1"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.2 Patch 9"
              },
              {
                "status": "affected",
                "version": "3.4 Patch 5"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 3"
              },
              {
                "status": "affected",
                "version": "3.5 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 10"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "Cisco ISE Passive Identity Connector",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.4.0"
              },
              {
                "status": "affected",
                "version": "3.5.0"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E7F4D769-1845-41F0-8F15-B5D8AC15DFD9",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "3CA3315D-8A45-43F4-A0F0-094D325F285B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B3736136-9FD8-4B12-B119-EA15201224D9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "FB15AE6D-F4EF-40AD-A88E-D22612AEF2A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "25B8E5EB-393A-40E8-9A0D-465ECCC2A4B8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "654ED77E-22D3-4E76-9E6D-B1581F5982F0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "A0648EE9-F042-479F-9AAB-C6B5DBC46511",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "83F3BA58-4F38-41C8-956F-38A2F44EECE4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "6C30FA1D-91E2-48C5-B181-A88FDF668278",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "768215B1-80B7-40FF-8772-BA4C0B3913F5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "40239DA8-43B6-466B-85B0-6D644D7027D1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "9118B7ED-E678-47C3-9D17-F522D9362B2F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "C2ED3257-CB9D-4FD5-A482-3648CF292128",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "7E30ECF6-5B1D-4280-AA02-123153E68F28",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "804C2F93-8ADC-454A-90DF-59F51FEF9E0A",
                "versionEndExcluding": "3.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "43F3A55D-D4FC-4D93-9513-94B64B21A2B4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*",
                "matchCriteriaId": "F0F60A00-E952-400A-B553-BE96E7FF746F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "BB069EA3-7B8C-42B5-8035-2EE5ED3F56E4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "FF8B81A6-BF44-4E5F-B167-39F61DDCA026",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "56E0F0EC-3E66-4866-89F5-89B331F3F517",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "2E3E8937-2859-4A2A-91C0-05F674EF0466",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "D4B14684-EB9E-405B-85FA-B62E57CB292C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "22B752D1-9E8F-4FB7-8EEB-F9234492372B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "85A1CC7D-FE54-4AC0-B98F-972C4B1F3189",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "A388D916-D6A1-4D3A-A48A-A150F387B755",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "719C8E82-269D-4F21-B2B4-4CD3033A17F9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. \r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system."
      }
    ],
    "id": "CVE-2026-20146",
    "lastModified": "2026-09-25T16:41:58.527",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 4.2,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20146",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-15T17:58:07.078523Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-15T17:16:46.970",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
zetlyn/cve-nvd · 2026-07-15
automatable no cvss 5.5 cvss_vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N cwe CWE-22 exploitation none product Cisco Identity Services Engine Software severity MEDIUM status Analyzed technical_impact partial vendor Cisco source