CVE-2026-20190
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20190 is an information disclosure vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that allows an unauthenticated, remote attacker to view sensitive information, including hashed credentials, on an affected device. It was first published on June 17, 2026, as part of a broader Cisco security advisory (cisco-sa-ise-multi-G5WP8vv) that also covers a related critical RCE vulnerability (CVE-2026-20181). Affected versions include Cisco ISE 3.4.0 through 3.4 Patch 5 and 3.5.0 through 3.5 Patch 2, as well as Cisco ISE-PIC 3.4.0 through 3.4 Patch 5 and 3.5.0 through 3.5 Patch 2. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is improper authorization (CWE-285): the affected ISE and ISE-PIC software fails to perform adequate authorization checks when certain resources are accessed. An unauthenticated remote attacker can exploit this by sending specially crafted network traffic to the affected device, bypassing access controls to reach protected resources. No authentication or user interaction is required, and the attack complexity is low, making it straightforward to automate. The vulnerability was reported by Bobby Gould of TrendAI Zero Day Initiative (Cisco Advisory). No public proof-of-concept code has been identified at this time (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to read sensitive information from the affected Cisco ISE or ISE-PIC device, most critically including hashed credentials. These hashed credentials could be leveraged in offline cracking or pass-the-hash attacks, potentially enabling lateral movement into broader enterprise network infrastructure that relies on ISE for authentication and policy enforcement. There is no direct integrity or availability impact from this vulnerability itself, but the credential exposure significantly elevates the risk of follow-on attacks (Cisco Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Cisco ISE or ISE-PIC instances running versions 3.4.0–3.4 Patch 5 or 3.5.0–3.5 Patch 2 using network scanning tools (e.g., Shodan, Censys, or Nmap).
  2. Craft malicious request: Construct an HTTP/HTTPS request targeting a resource endpoint on the ISE device that is subject to improper authorization checks, without supplying any authentication credentials.
  3. Send crafted traffic: Transmit the crafted request to the affected device over the network. The missing or insufficient authorization check allows access to the protected resource.
  4. Retrieve sensitive data: Parse the server's response to extract sensitive information, including hashed credentials stored or accessible by the ISE system.
  5. Post-exploitation: Use the obtained hashed credentials for offline password cracking or credential reuse attacks against other enterprise systems that rely on Cisco ISE for authentication (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous unauthenticated HTTP/HTTPS requests to Cisco ISE or ISE-PIC administrative or API endpoints from unknown or external IP addresses; repeated access attempts to sensitive resource paths without authentication headers.
  • Logs: ISE application logs showing access to protected resources by unauthenticated sessions; HTTP 200 responses to requests that should require authentication; unusual access patterns in the ISE audit logs for resource retrieval operations.
  • Process/Behavioral: Unusual outbound connections from the ISE node following inbound crafted requests; evidence of credential data being accessed outside of normal administrative workflows.

Mitigation and workarounds

Cisco has released fixed software to address CVE-2026-20190. Organizations should upgrade to the following fixed releases: Cisco ISE 3.4 Patch 6 (for the 3.4 train) or Cisco ISE 3.5 Patch 3 (for the 3.5 train). Cisco ISE-PIC 3.4 Patch 6 is the fixed release for ISE-PIC (note: ISE-PIC has reached end-of-sale, with 3.4 being the last supported release). There are no workarounds available for this vulnerability. As an interim measure, organizations should restrict network access to Cisco ISE and ISE-PIC management interfaces to only authorized hosts and networks, and monitor for suspicious unauthenticated access attempts (Cisco Advisory).

Community reactions

The vulnerability received notable coverage from security media outlets including SecurityWeek, SecurityAffairs, CyberSecurityNews, and The Hacker News, primarily in the context of the broader Cisco ISE advisory that also includes the critical RCE vulnerability CVE-2026-20181. The Singapore Cyber Security Agency (CSA) issued alerts (AL-2026-080 and AL-2026-081) referencing the Cisco ISE vulnerabilities. Qualys ThreatProtect published a dedicated analysis covering both CVE-2026-20181 and CVE-2026-20190. Community discussion on Reddit's r/Cisco focused on understanding affected versions and patch applicability. Overall sentiment emphasized urgency around patching given the sensitive nature of ISE's role in enterprise network access control (Cisco Advisory, Qualys ThreatProtect).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management