← All Advisories

CVE-2026-20190

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-20190

Key Details

CVECVE-2026-20190
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsCisco Identity Services Engine, Cisco Identity Services Engine Passive Identity Connector, Cisco Cisco Identity Services Engine Software, and Cisco Cisco ISE Passive Identity Connector
Classified asCWE-285 (Improper Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIdentity Services Engine
CiscoIdentity Services Engine Passive Identity Connector
CiscoCisco Identity Services Engine Software
CiscoCisco ISE Passive Identity Connector
SubsystemsIndustrial Network - Routers/Firewalls
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.

This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks. (NVD)

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20190
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20190
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv