---
id: CVE-2026-20193
title: "A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device.\r\n\r\nThi…"
summary: "A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device.\r\n\r\nThi…"
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
vendor: cisco
product: identity_services_engine
affected:
  - identity_services_engine <= 3.2.0
  - identity_services_engine = 3.3.0
  - identity_services_engine = 3.4.0
  - identity_services_engine = 3.5.0
published: '2026-05-06'
updated: '2026-07-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20193'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00221
epssPercentile: 0.11298
ingestedAt: '2026-07-01T15:50:58.810Z'
---

## Overview

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device.

This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized&nbsp;read access to sensitive RADIUS Policy details that are restricted for their role.

## Affected

- `identity_services_engine <= 3.2.0`
- `identity_services_engine = 3.3.0`
- `identity_services_engine = 3.4.0`
- `identity_services_engine = 3.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
