CVE-2026-20190
EUVD-2026-3774917.06.2026, 17:16
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | identity_services_engine | 3.4.0 |
| cisco | identity_services_engine | 3.4.0:patch1 |
| cisco | identity_services_engine | 3.4.0:patch2 |
| cisco | identity_services_engine | 3.4.0:patch3 |
| cisco | identity_services_engine | 3.4.0:patch4 |
| cisco | identity_services_engine | 3.4.0:patch5 |
| cisco | identity_services_engine | 3.5.0 |
| cisco | identity_services_engine | 3.5.0:patch1 |
| cisco | identity_services_engine | 3.5.0:patch2 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0:patch1 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0:patch2 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0:patch3 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0:patch4 |
| cisco | identity_services_engine_passive_identity_connector | 3.4.0:patch5 |
| cisco | identity_services_engine_passive_identity_connector | 3.5.0 |
| cisco | identity_services_engine_passive_identity_connector | 3.5.0:patch1 |
| cisco | identity_services_engine_passive_identity_connector | 3.5.0:patch2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration