Junglewise Threat Intelligence

CVE-2026-20195: Cisco ISE user enumeration in identity management API

CVE-2026-20195 · Severity: medium · CVSS 5.3 · Published 2026-05-06

Executive brief

A vulnerability in Cisco Identity Services Engine (ISE), a platform used for secure network access control, could allow an unauthorized person to identify valid user accounts. By sending specific requests to a management interface, an attacker can observe different error messages to confirm which usernames exist on the system. This information can be used to facilitate more targeted attacks, such as password guessing or phishing, against corporate users.

Technical details

An observable response discrepancy vulnerability (CWE-204) exists in the identity management API endpoint of Cisco Identity Services Engine (ISE). The vulnerability is caused by the API returning different error messages depending on whether a queried username is valid or invalid. An unauthenticated, remote attacker can exploit this by sending a series of crafted requests to the endpoint and analyzing the responses to compile a list of valid usernames. Cisco has released software updates to address this issue; no workarounds are available. Affected versions include 3.2 and earlier, 3.3, 3.4, and 3.5, with fixes provided in 3.3 Patch 11, 3.4 Patch 6, and 3.5 Patch 3.

Affected products

  • Cisco Identity Services Engine 3.2 and earlier, 3.3 (prior to Patch 11), 3.4 (prior to Patch 6), 3.5 (prior to Patch 3)

Timeline

  • 2026-05-06: advisory: Initial public release by Cisco
  • 2026-05-06: disclosed

References

Related threats