CVE-2026-20192
10.0Cisco · Identity Services Engine Software
Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector contain improper access control vulnerabilities discovered during internal security reviews.
Executive summary
A critical vulnerability in Cisco Identity Services Engine software could allow for improper access control, warranting immediate attention and patching.
Vulnerability
This vulnerability involves improper access control issues, classified under CWE-284, which were identified during a comprehensive internal security review of the affected software.
Business impact
The identified access control flaws carry a maximum CVSS score of 10.0, indicating the potential for total system compromise. An unauthenticated attacker could potentially bypass security restrictions to gain unauthorized access to sensitive network identity data and administrative functions, resulting in severe impacts on organizational security posture and regulatory compliance.
Remediation
Immediate Action: Upgrade to Cisco ISE Software Release 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4 as applicable.
Proactive Monitoring: Inspect system access logs for anomalous authentication patterns or unauthorized attempts to access management interfaces.
Compensating Controls: Ensure that management interfaces are isolated from public networks and accessible only via secured management VLANs or VPNs.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity rating, administrators should treat this update as a high-priority maintenance task. Organizations should schedule the recommended software patches as soon as possible to mitigate the risk posed by these access control weaknesses.
More Cisco CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section