CVE-2026-20283: Cisco ISE IPsec Open API Command Injection Vulnerability

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALCVE SIR: HIGHPUBLIC ANNOUNCEMENT: YESMALICIOUS USE: NOT REPORTED

Quick Answer

Cisco published a Critical-rated advisory that includes CVE-2026-20283, affecting Cisco Identity Services Engine (ISE) under the live advisory's conditions. Cisco explicitly lists the CVE-specific Security Impact Rating (SIR) as High; Common Vulnerability Scoring System (CVSS) base 6.5 (Medium). Confirm the exact platform, release, feature, and exposure; preserve relevant evidence; then follow Cisco's CVE-specific First Fixed guidance. Cisco reported that a public announcement was available, but said it was not aware of malicious use of this CVE at the last check. That status and absence from CISA KEV are time-bounded and do not prove exploitation has never occurred.

Fix Or Immediate Action

What to do now: Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Open the live Cisco advisory

Last verified: 2026-09-17 UTC from Cisco's advisory and CSAF record. Recheck both the affected-products and fixed-software sections before a production change.

Context

Scope And Impact In Plain Language

Who should check: Anyone who manages Cisco Identity Services Engine (ISE).

When this applies: This vulnerability affects Cisco ISE if there is more than one network interface and at least one of them is configured as an active IPsec tunnel between Cisco ISE and a physical Network Access Device (NAD).

What could happen: A successful attacker may be able to run attacker-chosen commands or software on the affected system, subject to the access and configuration requirements in the advisory.

Not sure? Find the exact product, platform, and version in the management interface or CLI, then compare them with this CVE's affected-products section in Cisco's live advisory.

Status At A Glance

Product scopeCisco Identity Services Engine (ISE)
CVECVE-2026-20283
TechGeeks response tierP1 — urgent
PublicationNew final Cisco advisory
First published2026-09-16T16:00:00+00:00
Last updated2026-09-16T16:00:00+00:00
Cisco advisory SIRCritical
CVE-specific Cisco SIRHigh
CVSS base score / severity6.5 — Medium
CVSS vectorCVSS v3.1 — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA KEV at last checkNo — this is separate from Cisco severity and is not proof of no exploitation.
Cisco exploitation statementThe Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory. The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.

Cisco SIR note: Cisco explicitly assigns High SIR rather than the Medium indicated by the numerical CVSS score because escalation to root is easy from the achieved privilege level.

What Happened

CVE-2026-20283: Cisco ISE IPsec Open API Command Injection Vulnerability A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. Bug ID(s): CSCwu31070 CVE ID: CVE-2026-20283 Security Impact Rating (SIR): High CVSS Base Score: 6.5 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Affected Scope

This vulnerability affects Cisco ISE if there is more than one network interface and at least one of them is configured as an active IPsec tunnel between Cisco ISE and a physical Network Access Device (NAD).

Match the exact hardware or virtual platform, installed train, patch level, enabled service, role, and management or data-plane exposure. A Cisco product-family name alone does not establish applicability.

Steps

What To Do Now

  1. Confirm. Inventory Cisco Identity Services Engine (ISE) and record platform, exact release, patch level, enabled feature, role, and exposure.
  2. Preserve. Save UTC context plus off-device authentication, management, firewall, network, endpoint, and SIEM evidence before logs rotate or a disruptive change removes context.
  3. Scope. Compare each asset with the live Cisco advisory, including configuration prerequisites and exclusions.
  4. Reduce exposure. Evaluate and apply Cisco's temporary workaround in the highlighted panel below; it does not replace the permanent fix.
  5. Remediate. Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.
  6. Validate. Confirm the resulting version, service health, logging, expected access, an expected denial, failover or cluster state, and representative dependent workflows.
  7. Escalate. If evidence or exposure creates concern, open incident response and Cisco TAC recovery work rather than treating patch completion as proof of trust.

Fixed Releases And Mitigation

Permanent Fix

Vendor-directed fix path: Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Cisco method: Use the live advisory's CVE-specific First Fixed Release table.

No compact per-CVE fixed-release table is reproduced here because Cisco may use different First Fixed values by CVE and software train. Use this CVE's live advisory table or Cisco Software Checker; do not infer a fixed release from a combined hardening baseline or another Cisco notice.

Workaround Or Temporary Mitigation

There is a workaround that addresses this vulnerability. The vulnerability is present only when an IPsec VTI tunnel is created using the API. However, using the Cisco ISE web interface to create an IPsec VTI tunnel does not allow the vulnerability to be configured. If a vulnerable configuration is present, do the following: Return to Administration > System > Settings > Protocols > IPsec > Native IPsec. Choose the tunnel with the vulnerable configuration and remove it. Add the tunnel back using the web interface. While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

Important boundary: A workaround, ACL, exposure reduction, or service restriction can reduce risk while the update is prepared, but it does not patch the vulnerable code, prove every attack path is closed, or erase an earlier compromise.

Investigation And Recovery

Review management authentication, account and privilege changes, API and web requests, configuration changes, crashes or restarts, resource pressure, and relevant external network telemetry for the vulnerable period. Preserve original evidence and follow Cisco TAC or incident-response guidance for containment, credential rotation, trusted rebuild, or service restoration when findings warrant it.

Notes

Exploitation Evidence

Cisco's exact status at the last check: The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory. The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.

This CVE was not present in the TechGeeks CISA KEV snapshot at the last check. Cisco's 'not aware' statement and absence from KEV are time-bounded evidence, not claims that exploitation is impossible or has never happened. Severity and exploitation status remain separate signals.

Validation And Boundaries

This notice is documentation-backed. TechGeeks did not reproduce the exploit or independently test every fixed build. It does not prove that all members of the product family are affected, that the activity is widespread, that a clean indicator search excludes compromise, or that an update restored trust. Cisco's live advisory controls affected and fixed release information.

Related TechGeeks Resources

References

Wrap-Up

Record whether CVE-2026-20283 applies. If it does, assign an owner and deadline appropriate to the Critical Cisco advisory SIR, preserve the evidence, complete Cisco's remediation, and document the validated result.

Correction policy: A material Cisco revision to scope, severity, exploitation status, workarounds, fixed software, or recovery guidance triggers an update and a new verification date.