RADIUS Policy API Vulnerability in Cisco ISE
CVE-2026-20193
4.3MEDIUM
What is CVE-2026-20193?
A security issue within the RADIUS Policy API of Cisco Identity Services Engine (ISE) can be exploited by authenticated remote attackers with read-only Administrator privileges. Due to misconfigured role-based access control (RBAC) settings, these attackers can bypass the standard web management interface to directly access sensitive RADIUS Policy API endpoints. This exploitation grants them unauthorized read access to restricted information, posing a significant risk to the confidentiality of data managed by Cisco ISE.
Affected Version(s)
Cisco Identity Services Engine Software 3.3.0
Cisco Identity Services Engine Software 3.3 Patch 2
Cisco Identity Services Engine Software 3.3 Patch 1