CVE-2026-20148 | Cisco Identity Services Engine Software HTTP path traversal (cisco-sa-ise-rce-traversal-8bYndVrZ / EUVD-2026-22963)
A vulnerability, which was classified as critical, has been found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. Affected by this issue is some unknown functionality of the component HTTP Handler. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-20148. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.