Cisco has patched a vulnerability in its Identity Services Engine (ISE) network access control solution, with public proof-of-concept exploit code, that can be abused by attackers with admin privileges. Enterprise admins use Cisco ISE to manage endpoint, user, and device access to network resources while enforcing a zero-trust architecture. The security flaw (CVE-2026-20029) affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration, and remote attackers with high privileges can exploit it to access sensitive information on unpatched devices. "This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application," Cisco said. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials." While the Cisco Product Security Incident Response Team (PSIRT) found no evidence of active exploitation, it did warn that a proof-of-concept (PoC) exploit is available online. Cisco considers "any workarounds and mitigations (if applicable) to be temporary solutions" and said that it "strongly recommends that customers upgrade to th...
Cisco warns of Identity Service Engine flaw with exploit code
BleepingComputer
·Sergiu Gatlan
·Published Jan 8, 2026
·Updated
Affected Software
2 affected components
Cisco Identity Services Engine=1.0
Cisco ISE Passive Identity Connector=1.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a recently patched vulnerability in Cisco's Identity Services Engine (ISE) that has exploit code publicly available.
2
What security implications are discussed in the article?
The article highlights that the vulnerability can be exploited by attackers with admin privileges, potentially compromising network security.
3
What products are affected by the vulnerability mentioned?
The affected products include Cisco Identity Services Engine and Cisco ISE Passive Identity Connector.
4
How can enterprises protect themselves from this vulnerability?
Enterprises are advised to apply the latest security patches provided by Cisco to mitigate the risk.
5
Is there any proof-of-concept exploit code available for this vulnerability?
Yes, the article mentions that there is public proof-of-concept exploit code available for the identified flaw.