CVE-2026-20195: Cisco Identity Services Engine Observable Response Discrepancy Vulnerability
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of valid usernames on an affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20195?
CVE-2026-20195 is classified as a high severity vulnerability.
How do I fix CVE-2026-20195?
To mitigate CVE-2026-20195, update your Cisco Identity Services Engine to the latest version provided by Cisco.
What impact does CVE-2026-20195 have on systems?
CVE-2026-20195 allows unauthenticated remote attackers to enumerate valid user accounts on affected devices.
Who is affected by CVE-2026-20195?
CVE-2026-20195 affects users of Cisco Identity Services Engine running vulnerable versions.
What actions should I take if I suspect exploitation of CVE-2026-20195?
If you suspect exploitation of CVE-2026-20195, immediately review logs for unauthorized access attempts and apply the relevant updates.