CVE-2026-20194: Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges. Exploitation does not require user interaction and can be performed over the network.
What impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impact as high, with scope changed. The vulnerability is rated critical with a CVSS score of 9.1.
Which products are identified as affected by this hardening release?
The advisory identifies Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Specific affected software versions are not provided in the available data.