Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
A command injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) due to insufficient validation of user-supplied input. An authenticated, remote attacker with valid administrative credentials can exploit this vulnerability by sending a crafted HTTP request to an affected device.
Successful exploitation allows attackers to execute arbitrary commands on the underlying operating system with user-level access, then elevate privileges to root. In single-node ISE deployments, this can cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition where unauthenticated endpoints cannot access the network until the node is restored. The vulnerability has a CVSS base score of 9.9 (HIGH severity) with high impacts to confidentiality, integrity, and availability.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
No patch information available at this time.
Given the severity (CVSS 9.9) and the requirement for valid administrative credentials, implement the following mitigation strategies: (1) Restrict administrative access to ISE and ISE-PIC instances to trusted personnel only; (2) Implement network-level access controls to limit who can reach ISE administrative interfaces; (3) Monitor ISE instances for suspicious HTTP requests or command execution attempts; (4) Review administrative access logs for unusual activity; (5) Monitor Cisco security advisories for patch availability and apply updates immediately when released; (6) For affected versions (ISE 3.1.x, 3.2.x, 3.3.x, 3.4.x, 3.5.x and ISE-PIC 3.1.0, 3.2.0, 3.3.0, 3.4.0), prioritize security updates. Consider isolating critical ISE nodes if patches are not immediately available.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Feedly found the first article mentioning CVE-2026-20147 . See article
NVD published the first details for CVE-2026-20147
A CVSS base score of 9.9 has been assigned.
CVE-2026-20147 is a critical vulnerability in Cisco ISE and Cisco ISE-PIC, rated 9.9 CVSS, allowing authenticated remote attackers to execute arbitrary commands on the underlying operating system, with potential for privilege escalation and denial of service in single-node deployments. There are no public proof-of-concept exploits or patch details available at this time, and the advisory does not specify whether the vulnerability is being actively exploited in the wild. Security researchers are encouraged to identify the specific input validation flaw to develop reliable exploits, as no mitigations are currently provided. See article
[GHSA-6m6h-8f8v-r7j4] A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, rem
CVE-2026-30995: Slah CMS SQL Injection in `vereador_ver.php`
Cisco ISE RCE via Authenticated Command Injection (CVE-2026-20147)
cisco cisco-sa-ise-rce-traversal-8bYndVrZ: Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
CVE-2026-20147 - Cisco Identity Services Engine Remote Code Execution Vulnerability CVE ID : CVE-2026-20147 Published : April 15, 2026, 5:17 p.m. | 40 minutes ago Description : A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker t...
CVE-2026-30995: Slah CMS SQL Injection in `vereador_ver.php`
CVE-2026-20147: Cisco Identity Services Engine Remote Code Execution Vulnerability [CRITICAL] CVSS 9.9
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
