CVE-2026-20190

EUVD-2026-37749
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.

This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
ciscoidentity_services_engine
3.4.0
ciscoidentity_services_engine
3.4.0:patch1
ciscoidentity_services_engine
3.4.0:patch2
ciscoidentity_services_engine
3.4.0:patch3
ciscoidentity_services_engine
3.4.0:patch4
ciscoidentity_services_engine
3.4.0:patch5
ciscoidentity_services_engine
3.5.0
ciscoidentity_services_engine
3.5.0:patch1
ciscoidentity_services_engine
3.5.0:patch2
ciscoidentity_services_engine_passive_identity_connector
3.4.0
ciscoidentity_services_engine_passive_identity_connector
3.4.0:patch1
ciscoidentity_services_engine_passive_identity_connector
3.4.0:patch2
ciscoidentity_services_engine_passive_identity_connector
3.4.0:patch3
ciscoidentity_services_engine_passive_identity_connector
3.4.0:patch4
ciscoidentity_services_engine_passive_identity_connector
3.4.0:patch5
ciscoidentity_services_engine_passive_identity_connector
3.5.0
ciscoidentity_services_engine_passive_identity_connector
3.5.0:patch1
ciscoidentity_services_engine_passive_identity_connector
3.5.0:patch2
𝑥
= Vulnerable software versions