Improper Authorization in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20190
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in a resource when accessing the resource. A remote attacker can send crafted traffic to disclose sensitive information.
Exposed information may include hashed credentials that could be used in future attacks.
Affected software
ISE Passive Identity Connector (ISE-PIC)
How to mitigate CVE-2026-20190
ISE Passive Identity Connector (ISE-PIC) - addressed in versions 3.4 Patch 6, 3.5 Patch 3