CVE-2026-20193
Cisco Identity Services Engine Authentication Bypass Vulnerability
Severity
Medium 4.3
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.7th percentile
Discovered by
Third party
Published by the vendor
Published
May 6, 2026
Assigned by cisco
Description
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.
Weakness: CWE-862
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Identity Services Engine (ISE) | Identity / IAM / MFA | cna-assigner |
Vendor-reported affected versions (1)
- Cisco · Cisco Identity Services Engine Software