Improper Authorization in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20190
Published: June 17, 2026
Cisco Identity Services Engine (ISE)
ISE Passive Identity Connector (ISE-PIC)
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in a resource when accessing the resource. A remote attacker can send crafted traffic to disclose sensitive information.
Exposed information may include hashed credentials that could be used in future attacks.