CVE-2026-20190: Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Cisco ISE and ISE-PIC management and API endpoints to trusted IP addresses using firewall rules or ACLs; block or limit unauthenticated remote access from untrusted networks.
- Operational
Rotate and reset any credentials that may have been exposed, including forcing password resets and invalidating related hashed credentials for impacted accounts and services.
- Operational
Investigate logs and audit access to determine whether sensitive information or hashed credentials were accessed or exfiltrated and identify affected accounts for remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20190?
The severity of CVE-2026-20190 is rated as high with a score of 7.5.
What systems are affected by CVE-2026-20190?
CVE-2026-20190 affects Cisco Identity Services Engine (ISE) and Cisco ISE-PIC.
How do I fix CVE-2026-20190?
To fix CVE-2026-20190, apply the latest security patches provided by Cisco for affected products.
What type of vulnerability is CVE-2026-20190?
CVE-2026-20190 is an information disclosure vulnerability due to improper authorization checks.
What could an attacker gain by exploiting CVE-2026-20190?
An attacker exploiting CVE-2026-20190 could gain access to view sensitive information on the affected device.