---
schema: 1
kind: vulnerability
title: "CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution"
headline: "CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution"
summary: "A dense critical-patch cycle landed in widely-deployed CH/EU public-sector infrastructure within 36 h: Cisco ISE, pgAdmin 4, NGINX, and Drupal core. The standout is the Cisco ISE pair (Cisco PSIRT, 2026-06-17): an unauthenticated attacker can read hashed administrator credentials (CVE-2026-20190), then reuse them to reach an authenticated path-traversal command-execution flaw that escalates to root (CVE-2026-20181, CVSS 9.1) — no workaround, and ISE 3.5's full fix slips to August. No in-the-wild exploitation is reported for any of these four advisories."
discovered_at: "2026-06-19T05:20:54Z"
event_date: 2026-06-18
run_id: 2026-06-19-c306b105
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - priv-esc
  - auth-bypass
  - info-disclosure
  - patch-available
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - education
  - finance
entities: []
cves:
  - id: CVE-2026-20181
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-20190
    cvss: "7.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv"
    publisher: Cisco PSIRT
    role: primary
  - url: "https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/"
    publisher: SecurityWeek
    role: corroborating
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1989"
    publisher: BSI CERT-Bund WID-SEC-2026-1989
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch Cisco ISE now and lock the management plane to admin subnets** (§ 2, § 5). Apply ISE 3.3 Patch 11 or 3.4 Patch 6; for ISE 3.5 apply Patch 3 immediately to close the unauthenticated credential read (CVE-2026-20190) and plan the August Patch 4 for CVE-2026-20181. There is no workaround — restrict the management/API interface to an out-of-band admin subnet, enforce MFA on admin logon, and alert on any off-subnet source reaching the ISE APIs."
migrated_from: briefs/2026-06-19.md
---

Cisco's advisory `cisco-sa-ise-multi-G5WP8vv` (2026-06-17) covers two flaws in ISE and ISE Passive Identity Connector ([Cisco PSIRT, 2026-06-17](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv); [SecurityWeek, 2026-06-18](https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/)). CVE-2026-20190 (improper authorization, CVSS 7.5) lets an unauthenticated remote attacker read sensitive data — including hashed administrator credentials — via crafted HTTP requests to specific APIs. CVE-2026-20181 (path traversal, CWE-22, CVSS 9.1) lets an authenticated administrator execute arbitrary OS commands and escalate to root; on single-node deployments it also causes a DoS. Cisco states there is **no workaround** and reports no known exploitation. Fixed in ISE 3.3 Patch 11 and 3.4 Patch 6 (available now); ISE 3.5 Patch 4 is scheduled for August 2026, with 3.5 Patch 3 closing only CVE-2026-20190 in the interim. The combined two-stage chain — and the detection/hardening for the identity plane it controls — is this brief's § 5 deep dive.
