ISE Admin Access Can Become OS Takeover

Cisco ISE and ISE-PIC are not just exposed to a leak bug here. A valid admin account can let an attacker turn the appliance into an operating-system foothold, and the separate unauthenticated disclosure flaw can hand out hashed credentials that may help set that up later. Cisco says CVE-2026-20181 lets an authenticated remote attacker run arbitrary commands on the underlying OS, and CVE-2026-20190 lets an unauthenticated attacker view sensitive information, including hashed credentials. Cisco has released updates for both, and there are no workarounds. The practical risk is bigger than a routine appliance patch. If ISE is the control point for network access or identity decisions, compromise of its admin plane can expose secrets and, in single-node deployments, take the node offline and block new authentication.

Part of the PlainSec briefing for 2026-06-19

Sources