CVE-2026-20072
ISE information disclosure
Description
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators.
Weakness: CWE-863
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Identity Services Engine (ISE) Check your version | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Identity Services Engine Software
Vendor advisory
cisco-sa-ise-multi-vuln-kWLeNnRD
Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities
Cisco’s rating: Medium (advisory CVSS 4.9) · Published Sep 16, 2026
Bug IDs: CSCwp98022 , CSCwp98024
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from