Resource Transfer Vulnerability in Cisco Identity Services Engine and Passive Identity Connector
CVE-2026-20194

9.1CRITICAL

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20194?

Cisco has announced a software hardening release for its Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC) as a result of an extensive internal security review. This review has identified vulnerabilities related to the incorrect transfer of resources between different operational spheres, categorized under the Common Weakness Enumeration (CWE) Pillar 669. The fix aims to enhance the security postures of these products by addressing the underlying issues discovered during this proactive security initiative.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.