CVE-2026-20193
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20193 is an authorization bypass vulnerability in the RADIUS Policy API endpoints of Cisco Identity Services Engine (ISE) that allows an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive RADIUS Policy information. The vulnerability was disclosed on May 6, 2026, as part of Cisco Security Advisory cisco-sa-ise-unauth-bypass-uxjRXGpb, which also covers a companion vulnerability (CVE-2026-20195). Affected versions include Cisco ISE 3.3 (all patches through Patch 10), 3.4 (all patches through Patch 5), 3.5 (patches 1 and 2), and 3.6 is not affected; versions 3.2 and earlier must migrate to a fixed release. It carries a CVSS v3.1 base score of 4.3 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is improper role-based access control (RBAC) enforcement on the RADIUS Policy API endpoints in Cisco ISE, classified as CWE-862 (Missing Authorization). The web-based management interface enforces role restrictions, but the underlying API endpoints do not apply equivalent authorization checks, allowing a low-privileged (read-only Administrator) authenticated user to bypass the UI and directly invoke restricted API endpoints over the network. No special conditions or user interaction are required beyond possessing a valid read-only Administrator account. Cisco Bug ID CSCwr77441 tracks this issue (Cisco Advisory).

Impact

Successful exploitation allows an authenticated attacker with limited (read-only Administrator) privileges to read sensitive RADIUS Policy configuration details that should be inaccessible to their role. The impact is limited to confidentiality — there is no integrity or availability impact — but exposure of RADIUS Policy details could reveal network access control configurations, shared secrets, or policy logic that could facilitate further attacks against network authentication infrastructure. Cisco ISE Passive Identity Connector (ISE-PIC) is confirmed not affected (Cisco Advisory).

Exploitation steps

  1. Obtain credentials: Acquire valid read-only Administrator credentials for the target Cisco ISE instance, either through phishing, credential stuffing, or insider access.
  2. Authenticate to ISE: Log in to the Cisco ISE instance using the read-only Administrator account to obtain a valid session token or API credentials.
  3. Identify RADIUS Policy API endpoints: Enumerate the ISE REST API documentation or probe known API paths (e.g., /api/v1/policy/radius/...) to identify RADIUS Policy endpoints that are accessible outside the web UI.
  4. Bypass the web UI: Instead of using the web-based management interface (which enforces RBAC restrictions), craft direct HTTP/HTTPS API requests to the affected RADIUS Policy endpoints using the authenticated session.
  5. Retrieve sensitive data: Parse the API responses to extract sensitive RADIUS Policy details — such as policy rules, conditions, or configuration parameters — that are restricted for the read-only Administrator role (Cisco Advisory).

Indicators of compromise

  • Network: Unusual direct API calls to Cisco ISE RADIUS Policy API endpoints (e.g., paths under /api/v1/policy/radius/) originating from read-only Administrator accounts, particularly outside normal administrative hours or from unexpected source IPs.
  • Logs: Cisco ISE audit logs showing API access to RADIUS Policy endpoints by accounts with read-only Administrator roles; repeated or scripted API queries to policy endpoints that would not normally be accessed via the web UI.
  • Behavior: A read-only Administrator account making a high volume of API requests to policy-related endpoints in a short time window, suggesting automated enumeration of RADIUS Policy configurations.

Mitigation and workarounds

Cisco has released fixed software versions: ISE 3.3 Patch 11, ISE 3.4 Patch 6, and ISE 3.5 Patch 3. ISE 3.6 is not vulnerable. Customers running ISE 3.2 or earlier must migrate to a supported fixed release. Cisco has confirmed there are no workarounds available for this vulnerability, so upgrading to a fixed release is the only remediation. Additionally, organizations should implement network-level access controls to restrict direct API access to ISE management interfaces and review RBAC policies for administrative accounts (Cisco Advisory).

Community reactions

The vulnerability was noted in weekly threat landscape digests and security monitoring feeds shortly after disclosure, but has not generated significant public commentary or media coverage given its medium severity and requirement for authenticated access. Cisco credited an external researcher for reporting the vulnerability. No notable researcher commentary or social media discussion beyond routine CVE tracking has been identified (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management