CVE-2026-20193

EUVD-2026-27862
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device.

This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.67%
Affected Products (NVD)
VendorProductVersion
ciscoidentity_services_engine
𝑥
≤ 3.2.0
ciscoidentity_services_engine
3.3.0
ciscoidentity_services_engine
3.3.0:patch1
ciscoidentity_services_engine
3.3.0:patch10
ciscoidentity_services_engine
3.3.0:patch2
ciscoidentity_services_engine
3.3.0:patch3
ciscoidentity_services_engine
3.3.0:patch4
ciscoidentity_services_engine
3.3.0:patch5
ciscoidentity_services_engine
3.3.0:patch6
ciscoidentity_services_engine
3.3.0:patch7
ciscoidentity_services_engine
3.3.0:patch8
ciscoidentity_services_engine
3.3.0:patch9
ciscoidentity_services_engine
3.4.0
ciscoidentity_services_engine
3.4.0:patch1
ciscoidentity_services_engine
3.4.0:patch2
ciscoidentity_services_engine
3.4.0:patch3
ciscoidentity_services_engine
3.4.0:patch4
ciscoidentity_services_engine
3.4.0:patch5
ciscoidentity_services_engine
3.5.0
ciscoidentity_services_engine
3.5.0:patch1
ciscoidentity_services_engine
3.5.0:patch2
𝑥
= Vulnerable software versions