CVE-2026-20190
Severity CVSS v4.0:
Pending analysis
Type:
CWE-285
Improper Authorization
Publication date:
17/06/2026
Last modified:
22/06/2026
Description
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.<br />
<br />
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



