BlockBreach Logo

Cisco Patches ISE Security Vulnerability: PoC Exploit Released for CVE-2026-20029

Published: 2026-01-08T00:00:00.000Z

Author: BlockBreach Team

"This vulnerability is due to improper parsing of XML... An attacker could exploit this vulnerability by uploading a malicious file to the application."

Cisco has rolled out critical updates to address a medium-severity security flaw affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), has garnered significant attention due to the release of a public Proof-of-Concept (PoC) exploit.

The Vulnerability: CVE-2026-20029

The flaw resides in the licensing feature of the web-based management interface. It stems from improper parsing of XML data. While the CVSS score is 4.9 (Medium), the implications are serious:

  • Access Level: Requires an authenticated remote attacker with administrative privileges.
  • Impact: Successful exploitation allows the attacker to read arbitrary files from the underlying operating system—files that should be restricted even from administrators.

The issue was discovered and reported by Bobby Gould of the Trend Micro Zero Day Initiative.

Affected Versions and Patches

Administrators are urged to upgrade immediately. Cisco has stated there are no workarounds for this vulnerability.

ISE / ISE-PIC Release Recommended Action
Earlier than 3.2 Migrate to a fixed release
3.2 Upgrade to 3.2 Patch 8
3.3 Upgrade to 3.3 Patch 8
3.4 Upgrade to 3.4 Patch 4
3.5 Not vulnerable

Additional Snort 3 Vulnerabilities

In addition to the ISE flaw, Cisco shipped fixes for two other medium-severity bugs impacting the Snort 3 Detection Engine, often used in Cisco Secure Firewall Threat Defense (FTD), IOS XE, and Meraki software. These flaws involve the processing of DCE/RPC requests:

CVE-2026-20026 (CVSS 5.8)

Snort 3 DCE/RPC denial-of-service vulnerability. Could cause the detection engine to restart.

CVE-2026-20027 (CVSS 5.3)

Snort 3 DCE/RPC information disclosure vulnerability. Could leak sensitive information.

How BlockBreach Can Help

Vulnerabilities in critical infrastructure like Cisco ISE can expose your network's "keys to the kingdom." BlockBreach's Vulnerability Assessment and Penetration Testing (VAPT) services can help you identify unpatched systems, validate your segmentation policies, and ensure your authentication infrastructure is secure against both internal and external threats.

Read Next