ctipilot.ch

Cisco ISE / ISE-PIC — authenticated path-traversal OS command execution to root (CVSS 9.1)

cve · CVE-2026-20181

Coverage timeline
3
first 2026-06-19 → last 2026-06-22
Peak priority
high
1 high · 2 notable
Sources cited
3
3 hosts
Sections touched
3
deep-dive, trending-vulnerabilities, weekly-vuln-rollup
Co-occurring entities
1
see Related entities below
ATT&CK techniques
8
pinned v19.1 · see below

ATT&CK techniques

8 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Defense Impairment TA0112

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Credential Access TA0006

T1110.002Brute Force: Password Cracking×1

Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained. OS Credential Dumping can be used to obtain password hashes, this may only get an adversary so far when Pass the Hash is not an option. Further, adversaries may leverage Data from Configuration Repository in order to obtain hashed credentials for network devices.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

T1212Exploitation for Credential Access×1

Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Lateral Movement TA0008

T1550Use Alternate Authentication Material×1

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.

Evidence: 2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c · ATT&CK page ↗

Story timeline

  1. 2026-06-22CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to root command execution
    weekly-vuln-rollup
  2. 2026-06-19CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution
    trending-vulnerabilities
  3. 2026-06-19Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane
    deep-dive

Where this entity is cited

  • deep-dive1
  • trending-vulnerabilities1
  • weekly-vuln-rollup1

Source distribution

  • sec.cloudapps.cisco.com1 (33%)
  • securityweek.com1 (33%)
  • wid.cert-bund.de1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Cisco ISE / ISE-PIC — authenticated path-traversal OS command execution to root (CVSS 9.1) (3)

2026-06-22 · view entry permalink →

CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to root command execution

Two flaws in Cisco ISE and the ISE Passive Identity Connector let an unauthenticated attacker read credentials (CVE-2026-20181, 9.1) that chain to authenticated root command execution (CVE-2026-20190, 7.5); BSI flagged the pair for DACH operators (Cisco PSIRT; daily 06-19). ISE is the network-access-control and policy backbone in many enterprise and public-sector networks — a rooted ISE undermines NAC posture wholesale. Patch promptly.

vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-19 · view entry permalink →

Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane

Cisco Identity Services Engine is not just another exposed appliance — it is the policy brain of network access control in most large Swiss and European public-sector estates: the RADIUS/TACACS+ server behind 802.1X port authentication, the posture/profiling engine, and frequently the AD/identity-policy enforcement point for both wired and wireless. A root shell on an ISE node is therefore not an endpoint compromise; it is control of the authentication plane that decides which devices and users get onto the network. That is what makes the pair Cisco patched on 2026-06-17 worth a deep read even with no in-the-wild exploitation yet reported (Cisco PSIRT, 2026-06-17).

The two primitives. CVE-2026-20190 (CVSS 7.5, improper authorization) is the entry primitive: specific ISE/ISE-PIC APIs fail to enforce authorization, so an unauthenticated remote attacker who can reach the management interface over HTTP can read sensitive data — explicitly including hashed administrator credentials — with crafted requests (T1190 Exploit Public-Facing Application → T1212 Exploitation for Credential Access). CVE-2026-20181 (CVSS 9.1, path traversal / CWE-22) is the impact primitive: an authenticated administrator can submit a crafted request that escapes the intended directory and executes arbitrary operating-system commands, escalating to root; on single-node deployments the same flaw can also be driven to a denial-of-service (SecurityWeek, 2026-06-18).

Why the chain matters more than either CVE. On its own, CVE-2026-20181 requires administrator authentication — a meaningful barrier. CVE-2026-20190 removes that barrier: it hands an unauthenticated attacker the hashed admin credentials, which can then be cracked offline (T1110.002 Password Cracking) or, depending on the credential material and authentication scheme, replayed (T1550 Use Alternate Authentication Material). With administrator authentication in hand (T1078 Valid Accounts), the attacker pivots to CVE-2026-20181 for command execution as root (T1059 Command and Scripting Interpreter → T1068 Exploitation for Privilege Escalation). The net effect is a network-reachable, no-interactive-credential path from "can talk to the ISE management plane" to "root on the identity controller." From root on ISE, an adversary is positioned to tamper with authentication and authorization policy itself (T1556 Modify Authentication Process) — issuing or trusting RADIUS responses, weakening 802.1X enforcement, or harvesting credentials traversing the policy engine.

Exposure and prerequisites. The only hard prerequisite for the entry primitive is network reachability of the ISE management/API interface; everything after that is consequence. Cisco states there is no workaround. Affected trains are fixed in ISE 3.3 Patch 11 and 3.4 Patch 6 (both available now). ISE 3.5 is the gap: Patch 3 closes only the unauthenticated read (CVE-2026-20190), and the full fix (Patch 4) is not scheduled until August 2026 — so 3.5 operators carry the authenticated-RCE half for roughly two months and must compensate with exposure reduction.

Hunt and detection concepts. Because there is no public exploit detail yet, detection here is behavioural and access-surface-oriented, not signature-based:

  • Management-plane reachability is the first control: alert on any source outside your defined administration subnets reaching the ISE management/API interface at all. The unauthenticated read only works if the attacker can reach those APIs.
  • API-access anomalies: review ISE application/admin logs for unauthenticated or unexpected requests to the credential-adjacent API endpoints, and for ERS/API request patterns from newly-seen source addresses.
  • Administrator-session anomalies: correlate any administrator CLI/command activity with the set of source addresses and accounts you expect to perform it; a successful chain shows up as admin-context command execution from an unusual origin shortly after anomalous unauthenticated API reads.
  • Identity-plane integrity: baseline expected RADIUS/TACACS+ behaviour and alert on policy or device-admin changes that did not originate from your change process — post-compromise tampering is the high-impact outcome to catch even if the intrusion itself was missed.

Hardening / mitigation (cite Cisco's own guidance). Apply the fixed patches as the only complete remediation: ISE 3.3 Patch 11 or 3.4 Patch 6 now; for 3.5, apply Patch 3 immediately to remove the unauthenticated credential read and plan the August Patch 4 upgrade. Independently of patch state, restrict the ISE management and API interfaces to dedicated, tightly-firewalled administration subnets (out-of-band management VLAN), enforce strong administrator credentials and MFA on admin logon to blunt the offline-cracking step, and monitor the management plane as a tier-0 asset. Treat ISE, like AD and the PKI, as identity infrastructure whose compromise is a full-network event — segment and instrument it accordingly.

vulnerability19 Jun 05:21Zmulti-sourceOpen finding ↗

2026-06-19 · view entry permalink →

CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution

Cisco's advisory cisco-sa-ise-multi-G5WP8vv (2026-06-17) covers two flaws in ISE and ISE Passive Identity Connector (Cisco PSIRT, 2026-06-17; SecurityWeek, 2026-06-18). CVE-2026-20190 (improper authorization, CVSS 7.5) lets an unauthenticated remote attacker read sensitive data — including hashed administrator credentials — via crafted HTTP requests to specific APIs. CVE-2026-20181 (path traversal, CWE-22, CVSS 9.1) lets an authenticated administrator execute arbitrary OS commands and escalate to root; on single-node deployments it also causes a DoS. Cisco states there is no workaround and reports no known exploitation. Fixed in ISE 3.3 Patch 11 and 3.4 Patch 6 (available now); ISE 3.5 Patch 4 is scheduled for August 2026, with 3.5 Patch 3 closing only CVE-2026-20190 in the interim. The combined two-stage chain — and the detection/hardening for the identity plane it controls — is this brief's § 5 deep dive.

vulnerability19 Jun 05:20Zmulti-sourceOpen finding ↗