Status: UPDATED | Advisory ID: CVE-2026-20190
| CVE | CVE-2026-20190 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Cisco Identity Services Engine, Cisco Identity Services Engine Passive Identity Connector, Cisco Cisco Identity Services Engine Software, and Cisco Cisco ISE Passive Identity Connector |
| Classified as | CWE-285 (Improper Authorization) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Cisco | Identity Services Engine | ||
| Cisco | Identity Services Engine Passive Identity Connector | ||
| Cisco | Cisco Identity Services Engine Software | ||
| Cisco | Cisco ISE Passive Identity Connector |
| Subsystems | Industrial Network - Routers/Firewalls |
| Sectors | Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems |
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks. (NVD)
Monitor Cisco's web page for any future patch releases. See vendor advisory link below.