Advisories
Cisco ISE 802.1X Session Hijack & Info Leak Vulnerabilities – Unauthenticated Local Attackers Can Bypass Auth
Cisco’s Identity Services Engine (ISE) now contains two medium‑risk flaws that let a local, unauthenticated user hijack an 802.1X session or pull sensitive data. The bugs, tracked as CVE‑2026‑20071 and CVE‑2026‑20072, expose attackers to authentication bypass and information disclosure. Cisco has issued patches; no workarounds exist. Systems must be updated promptly.
Security researchers have uncovered two critical weaknesses in Cisco’s Identity Services Engine (ISE) that could be leveraged by a local, unauthenticated attacker. The flaws enable session hijacking during 802.1X authentication and allow the extraction of confidential information.
What the Vulnerabilities Do
- Session Hijack (CVE‑2026‑20071): An attacker can intercept and take control of an ongoing 802.1X session, effectively bypassing the authentication process.
- Information Disclosure (CVE‑2026‑20072): Sensitive data stored in ISE can be read by the attacker, exposing credentials, network topology, and configuration details.
Impact
The bugs carry a medium severity rating. While they require local access, they can still compromise network integrity and confidentiality if an attacker gains foothold on a device running ISE.
Remediation
Cisco has released firmware updates that fix both issues. There are no available workarounds, so the only mitigation is to apply the latest patches immediately. Systems that cannot be updated should be isolated until a fix is applied.
Next Steps
- Verify your ISE version and compare against the latest release.
- Deploy the update as soon as possible.
- Review network logs for any signs of 802.1X session anomalies.
“We strongly recommend applying the Cisco ISE patches without delay to protect your network from potential exploitation.”