Junglewise Threat Intelligence

CVE-2026-20194: Cisco Identity Services Engine incorrect resource transfer vulnerability

CVE-2026-20194 · Severity: critical · CVSS 9.1 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) are network security products used to manage user access and authentication across enterprise networks. A critical vulnerability (CVE-2026-20194) in resource handling could allow attackers to expose sensitive information or bypass security controls, potentially compromising network access and user data across an organization's infrastructure.

Technical details

CVE-2026-20194 is grouped under CWE-669 (Incorrect resource transfer between spheres) and covers vulnerabilities related to exposure of sensitive information during transit, improper removal of sensitive information before storage, and unrestricted file upload. The vulnerability affects Cisco ISE and ISE-PIC regardless of device configuration. The issue was discovered during Cisco's internal security review and has a CVSS base score of 9.1 with a network attack vector requiring no authentication or user interaction. Patches are available in ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; ISE 3.0 and earlier have reached end-of-life and require migration to a supported release.

Affected products

  • Cisco Identity Services Engine 3.0 and earlier, 3.1 before patch 12, 3.2 before patch 11, 3.3 before patch 12, 3.4 before patch 7, 3.5 before patch 4
  • Cisco ISE Passive Identity Connector 3.4 and earlier

Timeline

  • 2026-09-16: disclosed: CVE-2026-20194 published as part of Cisco ISE hardening release security advisory
  • 2026-09-16: patched: Patches released for ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

References

Related threats