Junglewise Threat Intelligence

CVE-2026-20234: Cisco Identity Services Engine insufficiently protected credentials

CVE-2026-20234 · Severity: critical · CVSS 9.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain critical credential protection vulnerabilities discovered during internal security review. These appliances manage authentication, authorization, and accounting for enterprise networks. An attacker could potentially extract or misuse stored credentials, gaining unauthorized access to corporate systems and sensitive data.

Technical details

CVE-2026-20234 addresses insufficiently protected credentials (CWE-522) within a group of internally discovered vulnerabilities in Cisco ISE and ISE-PIC. The vulnerability allows unauthorized exposure or recovery of stored credentials, potentially through weak encoding, recoverable password storage, or similar authentication bypass mechanisms. The vulnerability is network-reachable and requires no authentication or user interaction to exploit. Attackers can extract credentials to gain unauthorized access to ISE and downstream systems. Cisco has released patched versions (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) and recommends immediate upgrade; no workarounds are available.

Affected products

  • Cisco Identity Services Engine 3.0 and earlier; 3.1, 3.2, 3.3, 3.4, 3.5 (various patch levels affected)
  • Cisco ISE Passive Identity Connector 3.4 and earlier

Timeline

  • 2026-09-16: disclosed: Public disclosure of CVE-2026-20234 and hardening release
  • 2026-09-16: patched: Fixed releases available: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

References

Related threats