Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2384 articles · 111906 vulns · 38/41 feeds (7d)
← Back to list
4.9
CVE-2026-20148EXPLOITED
cis · ise

Cisco Identity Services Engine Path Traversal Vulnerability

Description

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.

Affected Products

VendorProductVersions
cisise3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.2.0, 3.1.0, 3.3.0, 3.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco identity services engine (ise)cert_advisory90%
ciscisco ise passive identity connectormitre_affected90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ

Related News (5 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Cisco Identity Services Engine (ISE): Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security4d ago
Cisco: Kritische Codeschmuggel-Lücken in ISE und mehr geschlossen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Cisco (16 avril 2026)
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-20148 | Cisco Identity Services Engine Software HTTP path traversal (cisco-sa-ise-rce-traversal-8bYndVrZ)
→ No new info (linked only)
Tier A
Cisco Security5d ago
Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
→ No new info (linked only)
CVSS 3.14.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-22
PublishedApr 15, 2026
Last enriched5d agov2
Trending Score34
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20147EXP
Cisco Identity Services Engine Remote Code Execution Vulnerability
Trending: 87
CRITICALCVE-2026-20184
Cisco Webex Meetings Certificate Validation Vulnerability
Trending: 81
CRITICALCVE-2026-20180
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
Trending: 64
CRITICALCVE-2026-20186
Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
Trending: 64
MEDIUMCVE-2026-20132EXP
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Trending: 32

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 15, 2026
Discovered by ZDM
Apr 15, 2026
Updated: description, severity, exploitAvailable, activelyExploited
Apr 15, 2026
Actively Exploited
Apr 15, 2026
Exploit Available
Apr 15, 2026

Version History

v2
Last enriched 5d ago
v2Tier A5d ago

Updated severity to CRITICAL, added new vulnerabilities with CVE-IDs, and indicated that exploits are now available.

descriptionseverityexploitAvailableactivelyExploited
via Cisco Security
v15d ago

Initial creation