Summary
CVE-2026-20130 is a critical (CVSS 10.0) vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) caused by improper neutralization of special elements in output passed to a downstream component (CWE-74). The flaw was identified during Cisco’s internal security testing as part of a broad ISE hardening effort and could allow a remote, unauthenticated attacker to fully compromise confidentiality, integrity, and availability of an affected system. Cisco states it is not aware of any public exploitation or proof-of-concept code for this issue as of publication.
Technical details
- Root cause: Improper neutralization of special elements in data that is passed to a downstream component before being used, a weakness class that can manifest as command injection, code injection, XML injection, or resource injection depending on the specific code path exercised.
- Trigger conditions: An attacker sends crafted input to an affected ISE/ISE-PIC service; because the input is not properly sanitized before being handed off to a downstream component, it can be interpreted as executable content or commands rather than plain data.
- Attack vector: Network-based (AV:N), no privileges (PR:N) and no user interaction (UI:N) required, with low attack complexity (AC:L) — consistent with unauthenticated remote exploitation.
- Impact: Successful exploitation can result in full compromise of the affected device, with complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H) and a changed scope (S:C), indicating the ability to affect resources beyond the vulnerable component itself.
- Cisco disclosed this vulnerability as part of a coordinated hardening release addressing multiple internally discovered issues in ISE/ISE-PIC; no technical exploitation details or PoC have been publicly released.
Affected software
- Cisco Identity Services Engine (ISE) Software — versions 3.0 and earlier (migrate to a supported release), 3.1, 3.2, 3.3, 3.4, and 3.5, including all patch levels prior to the fixed releases below
- Cisco ISE Passive Identity Connector (ISE-PIC) — versions 3.1 through 3.5, prior to the fixed releases below
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to the fixed release corresponding to your current train:
- 3.0 and earlier → migrate to a supported, fixed release
- 3.1 → Patch 12
- 3.2 → Patch 11
- 3.3 → Patch 12
- 3.4 → Patch 7
- 3.5 → Patch 4
- If immediate patching is not possible: Cisco has confirmed there are no workarounds for this vulnerability; upgrading to a fixed patch release is the only remediation path. Limit network exposure of ISE administrative and service interfaces to trusted management networks as a compensating control until patches can be applied.
- Review Cisco’s advisory for the complete list of related CVEs disclosed in the same ISE hardening release, as several other critical- and high-severity issues were addressed concurrently and may require the same patch.

