CVE-2026-20190
Cisco Identity Services Engine Information Disclosure Vulnerability
Description
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Weakness: CWE-285
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco ISE Passive Identity Connector | Identity / IAM / MFA | cna-assigner |
| Cisco | Cisco Identity Services Engine (ISE) Check your version | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Identity Services Engine Software
- Cisco · Cisco ISE Passive Identity Connector
Vendor advisory
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Cisco’s rating: Critical (advisory CVSS 9.1) · Published Jun 17, 2026 · updated Jul 6, 2026 (revision 1.2)
Bug IDs: CSCwt22913 , CSCwt22936
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from