---
id: CVE-2026-20192
title: >-
  As part of Cisco's ongoing commitment to proactive security and product
  quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive
  Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive
  internal securi…
summary: >-
  As part of Cisco's ongoing commitment to proactive security and product
  quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive
  Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive
  internal securi…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.1.0
  - identity_services_engine_software 3.1.0 p1
  - identity_services_engine_software 3.1.0 p3
  - identity_services_engine_software 3.1.0 p2
  - identity_services_engine_software 3.2.0
  - identity_services_engine_software 3.1.0 p4
  - identity_services_engine_software 3.1.0 p5
  - identity_services_engine_software 3.2.0 p1
  - identity_services_engine_software 3.1.0 p6
  - identity_services_engine_software 3.2.0 p2
  - identity_services_engine_software 3.1.0 p7
  - identity_services_engine_software 3.3.0
  - identity_services_engine_software 3.2.0 p3
  - identity_services_engine_software 3.2.0 p4
  - identity_services_engine_software 3.1.0 p8
  - identity_services_engine_software 3.2.0 p5
  - identity_services_engine_software 3.2.0 p6
  - identity_services_engine_software 3.1.0 p9
  - identity_services_engine_software 3.3 Patch 2
  - identity_services_engine_software 3.3 Patch 1
  - identity_services_engine_software 3.3 Patch 3
  - identity_services_engine_software 3.4.0
  - identity_services_engine_software 3.2.0 p7
  - identity_services_engine_software 3.3 Patch 4
  - identity_services_engine_software 3.4 Patch 1
  - identity_services_engine_software 3.1.0 p10
  - identity_services_engine_software 3.3 Patch 5
  - identity_services_engine_software 3.3 Patch 6
  - identity_services_engine_software 3.4 Patch 2
  - identity_services_engine_software 3.3 Patch 7
  - identity_services_engine_software 3.4 Patch 3
  - identity_services_engine_software 3.5.0
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.3 Patch 8
  - identity_services_engine_software 3.2 Patch 8
  - identity_services_engine_software 3.5 Patch 1
  - identity_services_engine_software 3.3 Patch 9
  - identity_services_engine_software 3.2 Patch 9
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.5 Patch 2
  - identity_services_engine_software 3.3 Patch 10
  - identity_services_engine_software 3.3 Patch 11
  - identity_services_engine_software 3.4 Patch 6
  - identity_services_engine_software 3.2 Patch 10
  - identity_services_engine_software 3.1.0 p72
  - identity_services_engine_software 3.1.0 p11
  - ise_passive_identity_connector 3.2.0
  - ise_passive_identity_connector 3.1.0
  - ise_passive_identity_connector 3.3.0
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:17:16.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20192'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-18T03:55:53.856937Z'
epss: 0.00431
epssPercentile: 0.36802
ingestedAt: '2026-09-16T16:37:52.194Z'
---

## Overview

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20192 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-hardening-ise-XU5EwX5T** · Cisco · affected: Cisco Identity Services Engine Software (245 versions), Cisco ISE Passive Identity Connector (6 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T)
