CVE-2026-20190
published 2026-06-17CVE-2026-20190: A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.41%
33.0th percentile
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_ise_passive_identity_connector | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvelistv5v3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
ghsa_unreviewed·2026-06-17
CVE-2026-20190 [HIGH] CWE-285 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
CVEList
Cisco Identity Services Engine Information Disclosure Vulnerability
cvelistv5·2026-06-17·CVSS 7.5
CVE-2026-20190 [HIGH] CWE-285 Cisco Identity Services Engine Information Disclosure Vulnerability
Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
VulDB
Cisco Identity Services Engine Software 3.4.0/3.5.0 Traffic improper authorization (cisco-sa-ise-multi-G5WP8vv / EUVD-2026-37749)
vuldb·2026-06-17
CVE-2026-20190 [CRITICAL] Cisco Identity Services Engine Software 3.4.0/3.5.0 Traffic improper authorization (cisco-sa-ise-multi-G5WP8vv / EUVD-2026-37749)
A vulnerability was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector 3.4.0/3.5.0 and classified as critical. This issue affects some unknown processing of the component Traffic Handler. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-20190. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-06-17
Published