CVE-2026-20195
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-20195 is an Observable Response Discrepancy vulnerability in the identity management API endpoint of Cisco Identity Services Engine (ISE) that allows an unauthenticated, remote attacker to enumerate valid user accounts. The vulnerability was disclosed on May 6, 2026, and affects Cisco ISE releases 3.3, 3.4, and 3.5 (with specific patch levels), while release 3.6 and Cisco ISE Passive Identity Connector (ISE-PIC) are not affected. It carries a CVSS v3.1 base score of 5.3 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-204 (Observable Response Discrepancy): the affected identity management API endpoint returns differentiated error messages depending on whether a submitted username is valid or invalid, inadvertently leaking internal state to unauthenticated callers. An attacker exploits this by sending a series of crafted HTTP requests to the endpoint and analyzing the varying responses to distinguish valid from invalid usernames. No authentication or special privileges are required, and the attack can be conducted entirely over the network with low complexity. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to compile a list of valid usernames on the affected Cisco ISE device, resulting in a limited confidentiality impact. While there is no direct integrity or availability impact, the enumerated usernames can facilitate follow-on attacks such as credential stuffing, brute-force authentication attempts, or targeted phishing against ISE administrators and network access control users. Given ISE's role as a central network access control and policy enforcement platform, exposure of valid account names could meaningfully lower the barrier for further compromise of network infrastructure (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Cisco ISE instances running affected versions (3.3 prior to Patch 11, 3.4 prior to Patch 6, or 3.5 prior to Patch 3) using network scanning tools such as Nmap or Shodan.
  2. Locate the identity management API endpoint: Identify the specific ISE identity management API endpoint (e.g., REST API endpoints used for user account management) that returns differentiated error responses.
  3. Craft enumeration requests: Send a series of HTTP requests to the identified endpoint, varying the username field with candidate usernames (e.g., from a wordlist or common naming conventions).
  4. Analyze differential responses: Compare the error messages or response codes returned for each request — valid usernames will produce a distinct response compared to invalid ones, allowing the attacker to distinguish existing accounts.
  5. Compile username list: Aggregate all usernames that produced the "valid user" response pattern to build a list of confirmed accounts for use in subsequent attacks such as password spraying or targeted phishing (Cisco Advisory).

Indicators of compromise

  • Network: High volume of unauthenticated HTTP requests to Cisco ISE identity management API endpoints from a single or small set of source IP addresses; sequential or pattern-based username submissions in API request bodies.
  • Logs: ISE API access logs showing repeated requests to identity management endpoints with varying usernames and no successful authentication; unusual spikes in API error responses (e.g., "user not found" vs. other error types) from external or unexpected source IPs.
  • Behavioral: Automated, rapid-fire request patterns to the identity management API endpoint inconsistent with normal administrative usage; requests originating from IP addresses not associated with known administrators or management networks.

Mitigation and workarounds

Cisco has released fixed software versions to address this vulnerability: ISE 3.3 Patch 11, ISE 3.4 Patch 6, and ISE 3.5 Patch 3. ISE release 3.6 is not vulnerable, and ISE 3.2 and earlier should migrate to a fixed release. Cisco has confirmed there are no workarounds available for this vulnerability. As interim risk reduction measures, administrators should restrict network access to the ISE identity management API endpoints to trusted management networks only, and consider implementing rate limiting on the affected endpoint to slow enumeration attempts (Cisco Advisory).

Community reactions

Cisco credited an external researcher for reporting the vulnerability and confirmed through its PSIRT that no public exploitation or malicious use has been observed (Cisco Advisory). The vulnerability received routine coverage in threat intelligence aggregators and security news feeds shortly after disclosure, but no significant independent researcher commentary or notable social media discussion has been identified beyond standard CVE tracking.

Additional resources

  • Cisco Advisory — Official Cisco Security Advisory for cisco-sa-ise-unauth-bypass-uxjRXGpb
  • GitHub Advisory — GitHub Advisory Database entry GHSA-63pc-j336-8qq4
  • CVE Record — Official CVE.org record for CVE-2026-20195

SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management