
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20195 is an Observable Response Discrepancy vulnerability in the identity management API endpoint of Cisco Identity Services Engine (ISE) that allows an unauthenticated, remote attacker to enumerate valid user accounts. The vulnerability was disclosed on May 6, 2026, and affects Cisco ISE releases 3.3, 3.4, and 3.5 (with specific patch levels), while release 3.6 and Cisco ISE Passive Identity Connector (ISE-PIC) are not affected. It carries a CVSS v3.1 base score of 5.3 (Medium) (Cisco Advisory, GitHub Advisory).
The root cause is classified as CWE-204 (Observable Response Discrepancy): the affected identity management API endpoint returns differentiated error messages depending on whether a submitted username is valid or invalid, inadvertently leaking internal state to unauthenticated callers. An attacker exploits this by sending a series of crafted HTTP requests to the endpoint and analyzing the varying responses to distinguish valid from invalid usernames. No authentication or special privileges are required, and the attack can be conducted entirely over the network with low complexity. No public proof-of-concept code has been identified at this time (Cisco Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to compile a list of valid usernames on the affected Cisco ISE device, resulting in a limited confidentiality impact. While there is no direct integrity or availability impact, the enumerated usernames can facilitate follow-on attacks such as credential stuffing, brute-force authentication attempts, or targeted phishing against ISE administrators and network access control users. Given ISE's role as a central network access control and policy enforcement platform, exposure of valid account names could meaningfully lower the barrier for further compromise of network infrastructure (Cisco Advisory).
Cisco has released fixed software versions to address this vulnerability: ISE 3.3 Patch 11, ISE 3.4 Patch 6, and ISE 3.5 Patch 3. ISE release 3.6 is not vulnerable, and ISE 3.2 and earlier should migrate to a fixed release. Cisco has confirmed there are no workarounds available for this vulnerability. As interim risk reduction measures, administrators should restrict network access to the ISE identity management API endpoints to trusted management networks only, and consider implementing rate limiting on the affected endpoint to slow enumeration attempts (Cisco Advisory).
Cisco credited an external researcher for reporting the vulnerability and confirmed through its PSIRT that no public exploitation or malicious use has been observed (Cisco Advisory). The vulnerability received routine coverage in threat intelligence aggregators and security news feeds shortly after disclosure, but no significant independent researcher commentary or notable social media discussion has been identified beyond standard CVE tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."