CVE-2026-20190
Cisco Identity Services Engine Information Disclosure Vulnerability
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
40.3th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 17, 2026
Assigned by cisco
Description
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Weakness: CWE-285
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco ISE Passive Identity Connector | Identity / IAM / MFA | cna-assigner |
| Cisco | Cisco Identity Services Engine (ISE) | Identity / IAM / MFA | cna-assigner |
Vendor-reported affected versions (2)
- Cisco · Cisco Identity Services Engine Software
- Cisco · Cisco ISE Passive Identity Connector