Executive brief
Cisco Identity Services Engine (ISE) is a security platform used to manage network access and security policies. A vulnerability in its management interface could allow a user who already has limited, read-only administrative access to view sensitive security policy details they are not authorized to see. This could lead to the exposure of internal network configuration and security rules, potentially aiding further unauthorized activities.
Technical details
This vulnerability is classified as an improper role-based access control (RBAC) issue within the RADIUS Policy API endpoints of Cisco ISE. An authenticated attacker with low-privileged (read-only) administrative credentials can bypass the standard web-based management interface restrictions by directly calling the affected API endpoints. Successful exploitation allows the attacker to retrieve sensitive RADIUS Policy details that should be restricted based on their assigned role. The issue is addressed in Cisco ISE releases 3.3 Patch 11, 3.4 Patch 6, and 3.5 Patch 3. No workarounds are available.
Affected products
- Cisco Identity Services Engine (ISE) 3.2 and earlier, 3.3 prior to Patch 11, 3.4 prior to Patch 6, 3.5 prior to Patch 3
Timeline
- 2026-05-06: advisory: Initial public release by Cisco
- 2026-05-06: patched