Improper Access Control in Cisco Identity Services Engine and ISE Passive Identity Connector
CVE-2026-20192

10CRITICAL

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20192?

Cisco has enhanced the security of its Identity Services Engine and ISE Passive Identity Connector following a comprehensive internal review. The vulnerabilities identified pertain to improper access control, categorized under CWE-284. This software hardening release aims to bolster defenses against these vulnerabilities, ensuring that access controls are properly managed and enforced, thus protecting sensitive data and system integrity.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.