Junglewise Threat Intelligence

CVE-2026-20192: Cisco Identity Services Engine improper access control

CVE-2026-20192 · Severity: critical · CVSS 10 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE), a critical authentication and network access control platform, contains improper access control vulnerabilities that could allow attackers to bypass security restrictions. One vulnerability in this class is known to be actively exploited in the wild. An attacker could potentially gain unauthorized access to network resources and administrative functions without proper authentication, leading to data breach, network compromise, or complete system takeover.

Technical details

This vulnerability (grouped under CVE-2026-20192 for CWE-284) represents improper access control issues including authorization, authentication, and privilege bypass flaws. The vulnerability affects Cisco ISE and ISE Passive Identity Connector (ISE-PIC) products regardless of device configuration. The attack vector is network-based with no authentication or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N/S:C). At least one vulnerability within this CWE category is actively exploited. Patches are available in fixed software releases (ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4), and customers should upgrade immediately.

Affected products

  • Cisco Identity Services Engine 3.0 and earlier, 3.1 before Patch 12, 3.2 before Patch 11, 3.3 before Patch 12, 3.4 before Patch 7, 3.5 before Patch 4
  • Cisco Identity Services Engine Passive Identity Connector through 3.4

Timeline

  • 2026-09-16: disclosed: Cisco security advisory published
  • exploited: One vulnerability in the access control class (CWE-284) is known to be actively exploited in the wild
  • 2026-09-16: patched: Fixed releases available: ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

References

Related threats