CVE-2026-20309
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Vulnerability report for CVE-2026-20309, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-18
Assigner: Cisco Systems, Inc.
Description
Description
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Cisco | Cisco | Identity Services Engine Software 3.1.0 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p1 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p3 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p2 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p4 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p5 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p1 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p6 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p2 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p7 |
| Cisco | Cisco | Identity Services Engine Software 3.3.0 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p3 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p4 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p8 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p5 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p6 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p9 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 2 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 1 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 3 |
| Cisco | Cisco | Identity Services Engine Software 3.4.0 |
| Cisco | Cisco | Identity Services Engine Software 3.2.0 p7 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 4 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 1 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p10 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 5 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 6 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 2 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 7 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 3 |
| Cisco | Cisco | Identity Services Engine Software 3.5.0 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 4 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 8 |
| Cisco | Cisco | Identity Services Engine Software 3.2 Patch 8 |
| Cisco | Cisco | Identity Services Engine Software 3.5 Patch 1 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 9 |
| Cisco | Cisco | Identity Services Engine Software 3.2 Patch 9 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 5 |
| Cisco | Cisco | Identity Services Engine Software 3.5 Patch 3 |
| Cisco | Cisco | Identity Services Engine Software 3.5 Patch 2 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 10 |
| Cisco | Cisco | Identity Services Engine Software 3.3 Patch 11 |
| Cisco | Cisco | Identity Services Engine Software 3.4 Patch 6 |
| Cisco | Cisco | Identity Services Engine Software 3.2 Patch 10 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p72 |
| Cisco | Cisco | Identity Services Engine Software 3.1.0 p11 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |