---
id: CVE-2026-20190
title: "A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.\r\n\r\nThis vulnerability is due to improper authorization checks when a resource is accessed"
summary: "A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.\r\n\r\nThis vulnerability is due to improper authorization checks when a resource is accessed. An a…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-285
vendor: cisco
product: identity_services_engine
affected:
  - identity_services_engine = 3.4.0
  - identity_services_engine = 3.5.0
  - identity_services_engine_passive_identity_connector = 3.4.0
published: '2026-06-17'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T16:41:47.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20190'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00504
epssPercentile: 0.40495
ingestedAt: '2026-09-25T17:13:13.994Z'
---

## Overview

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.

This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.

## Affected

- `identity_services_engine = 3.4.0`
- `identity_services_engine = 3.5.0`
- `identity_services_engine_passive_identity_connector = 3.4.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
