Improper Authorization in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20190

 

Improper Authorization in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20190

Published: June 17, 2026


Vulnerability identifier: #VU134761
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20190
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in a resource when accessing the resource. A remote attacker can send crafted traffic to disclose sensitive information.

Exposed information may include hashed credentials that could be used in future attacks.


Affected software

Cisco Identity Services Engine (ISE)
ISE Passive Identity Connector (ISE-PIC)

How to mitigate CVE-2026-20190

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.4 Patch 6, 3.5 Patch 3
ISE Passive Identity Connector (ISE-PIC) - addressed in versions 3.4 Patch 6, 3.5 Patch 3

External References

Related Security Bulletins