API Vulnerability in Cisco Identity Services Engine Allows Information Disclosure
CVE-2026-20235

4.9MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20235?

A vulnerability in the API of Cisco Identity Services Engine (ISE) permits authenticated remote attackers to access sensitive data from affected devices. This issue arises from inadequate validation of user-supplied parameters in API requests. An attacker with valid administrative credentials could initiate a specially crafted API request that exploits this vulnerability, potentially allowing access to hashed credentials and other sensitive information. This poses a risk of further attacks leveraging the compromised data. Ensuring secure API practices is critical to mitigating such vulnerabilities.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.