High severity7.5NVD Advisory· Published Jun 17, 2026· Updated Jun 22, 2026
CVE-2026-20190
CVE-2026-20190
Description
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.5.0:patch2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
5- ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure VulnerabilityZero Day Initiative · Aug 13, 2026
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Critical Cisco ISE Vulnerability Allows Attacker to Execute Malicious Code RemotelyCyber Security News · Jun 18, 2026
- Critical Command Execution Vulnerability Patched in Cisco ISESecurityWeek · Jun 18, 2026
- Cisco: Six CVEs Across Four Products, Including Actively Exploited SD-WAN Zero-DayVypr Intelligence · Jun 17, 2026