
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20190 is an information disclosure vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that allows an unauthenticated, remote attacker to view sensitive information, including hashed credentials, on an affected device. It was first published on June 17, 2026, as part of a broader Cisco security advisory (cisco-sa-ise-multi-G5WP8vv) that also covers a related critical RCE vulnerability (CVE-2026-20181). Affected versions include Cisco ISE 3.4.0 through 3.4 Patch 5 and 3.5.0 through 3.5 Patch 2, as well as Cisco ISE-PIC 3.4.0 through 3.4 Patch 5 and 3.5.0 through 3.5 Patch 2. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper authorization (CWE-285): the affected ISE and ISE-PIC software fails to perform adequate authorization checks when certain resources are accessed. An unauthenticated remote attacker can exploit this by sending specially crafted network traffic to the affected device, bypassing access controls to reach protected resources. No authentication or user interaction is required, and the attack complexity is low, making it straightforward to automate. The vulnerability was reported by Bobby Gould of TrendAI Zero Day Initiative (Cisco Advisory). No public proof-of-concept code has been identified at this time (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to read sensitive information from the affected Cisco ISE or ISE-PIC device, most critically including hashed credentials. These hashed credentials could be leveraged in offline cracking or pass-the-hash attacks, potentially enabling lateral movement into broader enterprise network infrastructure that relies on ISE for authentication and policy enforcement. There is no direct integrity or availability impact from this vulnerability itself, but the credential exposure significantly elevates the risk of follow-on attacks (Cisco Advisory, GitHub Advisory).
Cisco has released fixed software to address CVE-2026-20190. Organizations should upgrade to the following fixed releases: Cisco ISE 3.4 Patch 6 (for the 3.4 train) or Cisco ISE 3.5 Patch 3 (for the 3.5 train). Cisco ISE-PIC 3.4 Patch 6 is the fixed release for ISE-PIC (note: ISE-PIC has reached end-of-sale, with 3.4 being the last supported release). There are no workarounds available for this vulnerability. As an interim measure, organizations should restrict network access to Cisco ISE and ISE-PIC management interfaces to only authorized hosts and networks, and monitor for suspicious unauthenticated access attempts (Cisco Advisory).
The vulnerability received notable coverage from security media outlets including SecurityWeek, SecurityAffairs, CyberSecurityNews, and The Hacker News, primarily in the context of the broader Cisco ISE advisory that also includes the critical RCE vulnerability CVE-2026-20181. The Singapore Cyber Security Agency (CSA) issued alerts (AL-2026-080 and AL-2026-081) referencing the Cisco ISE vulnerabilities. Qualys ThreatProtect published a dedicated analysis covering both CVE-2026-20181 and CVE-2026-20190. Community discussion on Reddit's r/Cisco focused on understanding affected versions and patch applicability. Overall sentiment emphasized urgency around patching given the sensitive nature of ISE's role in enterprise network access control (Cisco Advisory, Qualys ThreatProtect).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."