cbcvebase.
CVE-2026-20190
published 2026-06-17

CVE-2026-20190: A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This…

PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.41%
33.0th percentile
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_ise_passive_identity_connector
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvelistv5v3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.