Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-20136

CVE-2026-20136: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityMedium6.0

    Medium [CVE-2026-20136] Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability

    cisco-sa-ise-cmd-inj-5WSJcYJBSource published Source updated

    A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

    Related products — impact not confirmed
    • ISE
    • Identity Services Engine Software
    Source-reported affected versions
    • Scope: At the time of publication, this vulnerability affected Cisco ISE and ISE-PIC, regardless of device configuration.
    • Release 3.3 and earlier (first fixed: 3.3 Patch 11 (Apr 2026))
    • Release 3.4 (first fixed: 3.4 Patch 6 (Apr 2026))
    • Release 3.51 (first fixed: 3.5 Patch 3)
    Source-reported fixed versions
    • 3.3 Patch 11 (Apr 2026)
    • 3.4 Patch 6 (Apr 2026)
    • 3.5 Patch 3
    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Release 3.3 and earlier: upgrade to 3.3 Patch 11 (Apr 2026).
    • Release 3.4: upgrade to 3.4 Patch 6 (Apr 2026).
    • Release 3.51: upgrade to 3.5 Patch 3.
    Workarounds
    • There are no workarounds that address this vulnerability.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery