Junglewise Threat Intelligence

CVE-2026-20235: Cisco Identity Services Engine API information disclosure

CVE-2026-20235 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is an authentication and network access control system used to manage user and device access to corporate networks. A vulnerability in its API allows authenticated administrators to view sensitive information on affected devices by sending specially crafted API requests, potentially exposing hashed credentials that could be used in future attacks.

Technical details

This vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient validation of user-supplied parameters in API requests. The vulnerability requires valid administrative credentials to exploit and is accessed via network vector with low attack complexity. An attacker with admin credentials can send a crafted API request to view sensitive information including hashed credentials. Cisco has released patches for affected versions: 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, with earlier versions requiring migration.

Affected products

  • Cisco Identity Services Engine Earlier than 3.3; 3.3 before Patch 12; 3.4 before Patch 7; 3.5 before Patch 4

Timeline

  • 2026-09-16: disclosed: Cisco Security Advisory published
  • 2026-09-16: patched: Fixed releases available: 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

References

Related threats