CVE-2026-20190

Cisco Identity Services Engine Information Disclosure Vulnerability

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
40.3th percentile
Discovered by
Third party
Published by the vendor
Published
Jun 17, 2026
Assigned by cisco

Description

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.

Weakness: CWE-285

Affected products

Vendor Product Category Matched by
Cisco Cisco ISE Passive Identity Connector Identity / IAM / MFA cna-assigner
Cisco Cisco Identity Services Engine (ISE) Identity / IAM / MFA cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco Identity Services Engine Software
  • Cisco · Cisco ISE Passive Identity Connector