identity services engine

Cisco Identity Services Engine Vulnerable to Command Injection
A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

Cisco Identity Services Engine Leaks Information Due to Missing Authentication
A critical vulnerability has been discovered in Cisco Identity Services Engine, allowing unauthenticated remote attackers to access sensitive information. The flaw stems from a missing authentication check for a critical function within the software. This could lead to significant data exposure on affected systems.

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal
A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.

Cisco Identity Services Engine Vulnerability Discloses Sensitive Information
A directory traversal vulnerability in Cisco Identity Services Engine allows authenticated remote attackers to access sensitive information. The vulnerability, assigned CVE-2026-20148, has a CVSS score of 4.9, indicating a medium severity.