Executive brief
Cisco Identity Services Engine (ISE) is a network access control and identity management platform used to authenticate users and devices on corporate networks. A vulnerability in its web-based management interface could allow an authenticated administrator to export user credentials from security groups they are not authorized to access, potentially exposing passwords and sensitive user information across the organization. This could lead to unauthorized network access and data breaches by compromised administrators.
Technical details
This is an authorization bypass vulnerability (CWE-863) in Cisco ISE's web-based management interface. The vulnerability exists in certain files that lack proper authorization enforcement when exporting user data. An attacker with administrative privileges and management rights over network users can exploit this by exporting users from security groups outside their authorized scope, bypassing access controls. The attack is network-based, requires high-level administrative privileges (PR:H), and does not require user interaction. A successful exploit allows the attacker to view passwords normally hidden from administrators. Cisco has released patches for ISE versions 3.2 through 3.5 with specific patch levels (3.2 Patch 8, 3.3 Patch 8 or 12, 3.4 Patch 7, 3.5 Patch 3 or 4); users on ISE 3.1 and earlier must migrate to a fixed release.
Affected products
- Cisco Identity Services Engine (ISE) 3.1 and earlier, 3.2 (before Patch 8), 3.3 (before Patch 8), 3.4 (before Patch 7), 3.5 (before Patch 3)
Timeline
- 2026-09-16: disclosed