CVE-2026-20195

EUVD-2026-27863
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device.

This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of valid usernames on an affected system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19.54%
Affected Products (NVD)
VendorProductVersion
ciscoidentity_services_engine
𝑥
≤ 3.2.0
ciscoidentity_services_engine
3.3.0
ciscoidentity_services_engine
3.3.0:patch1
ciscoidentity_services_engine
3.3.0:patch10
ciscoidentity_services_engine
3.3.0:patch2
ciscoidentity_services_engine
3.3.0:patch3
ciscoidentity_services_engine
3.3.0:patch4
ciscoidentity_services_engine
3.3.0:patch5
ciscoidentity_services_engine
3.3.0:patch6
ciscoidentity_services_engine
3.3.0:patch7
ciscoidentity_services_engine
3.3.0:patch8
ciscoidentity_services_engine
3.3.0:patch9
ciscoidentity_services_engine
3.4.0
ciscoidentity_services_engine
3.4.0:patch1
ciscoidentity_services_engine
3.4.0:patch2
ciscoidentity_services_engine
3.4.0:patch3
ciscoidentity_services_engine
3.4.0:patch4
ciscoidentity_services_engine
3.4.0:patch5
ciscoidentity_services_engine
3.5.0
ciscoidentity_services_engine
3.5.0:patch1
ciscoidentity_services_engine
3.5.0:patch2
𝑥
= Vulnerable software versions