CVE-2026-20193
EUVD-2026-2786206.05.2026, 17:16
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | identity_services_engine | 𝑥 ≤ 3.2.0 |
| cisco | identity_services_engine | 3.3.0 |
| cisco | identity_services_engine | 3.3.0:patch1 |
| cisco | identity_services_engine | 3.3.0:patch10 |
| cisco | identity_services_engine | 3.3.0:patch2 |
| cisco | identity_services_engine | 3.3.0:patch3 |
| cisco | identity_services_engine | 3.3.0:patch4 |
| cisco | identity_services_engine | 3.3.0:patch5 |
| cisco | identity_services_engine | 3.3.0:patch6 |
| cisco | identity_services_engine | 3.3.0:patch7 |
| cisco | identity_services_engine | 3.3.0:patch8 |
| cisco | identity_services_engine | 3.3.0:patch9 |
| cisco | identity_services_engine | 3.4.0 |
| cisco | identity_services_engine | 3.4.0:patch1 |
| cisco | identity_services_engine | 3.4.0:patch2 |
| cisco | identity_services_engine | 3.4.0:patch3 |
| cisco | identity_services_engine | 3.4.0:patch4 |
| cisco | identity_services_engine | 3.4.0:patch5 |
| cisco | identity_services_engine | 3.5.0 |
| cisco | identity_services_engine | 3.5.0:patch1 |
| cisco | identity_services_engine | 3.5.0:patch2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration