AI description
CVE-2026-20190 is an information disclosure vulnerability found in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This flaw allows an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability stems from improper authorization checks when a resource is accessed. An attacker can exploit this by sending specially crafted network requests to the affected Cisco ISE systems, enabling them to view sensitive data, including hashed credentials.
- Description
- A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- identity_services_engine, identity_services_engine_passive_identity_connector
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- psirt@cisco.com
- CWE-285
- Hype score
- Not currently trending
Warning: Cisco released security updates for critical CVE-2026-20181 and high-severity CVE-2026-20190 affecting Cisco ISE and Cisco ISE-PIC. Exploitation allows remote attackers to execute arbitrary code or access sensitive information. Patch Patch Patch https://t.co/498PsOC3kW
@CCBalert
19 Jun 2026
199 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#Cisco released Security Updates to address multiple Vulnerabilities in Cisco Identity Services Engine (#ISE) and Cisco ISE Passive Identity Connector (#ISE-PIC). Apply Updates! #CVE-2026-20181 #CVE-2026-20190 https://t.co/O1PO6arPQi
@NCIIPC
19 Jun 2026
166 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Cisco ISE patch watch: Cisco fixed CVE-2026-20181 and CVE-2026-20190 in ISE and ISE-PIC. The advisory says the flaws can enable remote code execution or sensitive information disclosure, with no workarounds. #Cisco #Cyber https://t.co/ElVl2jK4ES
@Divinmentis
18 Jun 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
『allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device.』 CVE-2026-20181 CVE-2026-20190 Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities https://t.co/f3fITtqm4R
@autumn_good_35
18 Jun 2026
292 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
【セキュリティ ニュース】「Cisco ISE」にRCE脆弱性 - 端末の接続に影響するおそれも(1ページ目 / 全2ページ):Security NEXT https://t.co/jk6yaf7Smc CVE-2026-20181/CVE-2026-20190 Cisco Identity Services Engineにおけるリモートコー
@taku888infinity
18 Jun 2026
1288 Impressions
1 Retweet
3 Likes
3 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-20190 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is… https://t.co/rPBBiO5uwh ----- Traducción: CVE-2026-20190 Una v… https://t.co/utmtNg
@infoflowcloud
17 Jun 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Cisco ISE vulnerabilities expose networks to Remote Code Execution (CVE-2026-20181) and data theft (CVE-2026-20190). Patch affected systems now. #CiscoISE #CyberSecurity #CVE202620181 #CVE202620190 #InfoSec https://t.co/Rdjc5MElon https://t.co/DhHIGCFdwU
@Daily_CyberSec
17 Jun 2026
414 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
"matchCriteriaId": "D23905E0-E525-49B1-8E5F-4EB42D186768",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
"matchCriteriaId": "74509498-38EF-4345-9583-CEF5C26CA1D8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*",
"matchCriteriaId": "CD05FF93-7B8C-4283-9DB7-E03FE98FAADF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*",
"matchCriteriaId": "0F9B6A8E-E773-44A3-9266-878F0C58EB41",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*",
"matchCriteriaId": "D3727619-E0CA-4CA9-BE35-0C732BCF1741",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*",
"matchCriteriaId": "2CFB7565-3930-409C-B5DB-CE77E6ED7C42",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*",
"matchCriteriaId": "2610FD35-BC4B-41B7-9C92-E6E5264FEE54",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*",
"matchCriteriaId": "3FEE4377-B238-4442-9892-28CECFB2319E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*",
"matchCriteriaId": "6598563B-7E32-43FB-96A7-88C53E4CE226",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
"matchCriteriaId": "CC0525FD-C4D7-4B48-BF35-1791391AB148",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*",
"matchCriteriaId": "68C96F6B-51EE-4D03-9598-CBFD16DA22EF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*",
"matchCriteriaId": "62F25185-D19E-4EC5-8A68-7AB669B76E90",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*",
"matchCriteriaId": "C457D2EC-FB63-49B7-A90E-CE67ED763BAE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*",
"matchCriteriaId": "6566330F-A048-44A1-9821-7A5844C82CEC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*",
"matchCriteriaId": "1154F196-2CB3-4AC2-BE00-11A8942EA999",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:-:*:*:*:*:*:*",
"matchCriteriaId": "2A7003EB-C578-4C02-B768-F8C4C8421382",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch1:*:*:*:*:*:*",
"matchCriteriaId": "16B32F60-CEB7-4816-AA7C-3130D1053DC5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch2:*:*:*:*:*:*",
"matchCriteriaId": "755761D7-8DDD-4219-8E37-FA535757710A",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]