CVE-2026-20192

10.0

Cisco · Identity Services Engine Software

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector contain improper access control vulnerabilities discovered during internal security reviews.

Executive summary

A critical vulnerability in Cisco Identity Services Engine software could allow for improper access control, warranting immediate attention and patching.

Vulnerability

This vulnerability involves improper access control issues, classified under CWE-284, which were identified during a comprehensive internal security review of the affected software.

Business impact

The identified access control flaws carry a maximum CVSS score of 10.0, indicating the potential for total system compromise. An unauthenticated attacker could potentially bypass security restrictions to gain unauthorized access to sensitive network identity data and administrative functions, resulting in severe impacts on organizational security posture and regulatory compliance.

Remediation

Immediate Action: Upgrade to Cisco ISE Software Release 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4 as applicable.

Proactive Monitoring: Inspect system access logs for anomalous authentication patterns or unauthorized attempts to access management interfaces.

Compensating Controls: Ensure that management interfaces are isolated from public networks and accessible only via secured management VLANs or VPNs.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity rating, administrators should treat this update as a high-priority maintenance task. Organizations should schedule the recommended software patches as soon as possible to mitigate the risk posed by these access control weaknesses.

More Cisco CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief critical section

Sources