CVE-2026-20193Disclosure(cisco / identity_services_engine)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
identity_services_engine

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 2Mentions · 2026-05-14: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-14: 105-0605-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure1General1
2026-05-141
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-20193 A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain una… https://www.cve.org/CVERecord?id=CVE-2026-20193

    Post summary

    The post briefly describes CVE-2026-20193 affecting Cisco ISE's RADIUS Policy API but provides no PoC, exploit code, patch, or detailed technical data.

    00010149
    57.4K followersView on X
  • UWillC@uwillc
    Disclosure

    Cisco PSIRT May 6 bundle: 6 advisories. Headlines: ISE auth-bypass CVE-2026-20193 (CVSS 4.3, Medium). The one nobody read: CVE-2026-20034 Unity Connection RCE-as-root (CVSS 8.8, High, no workaround). If you rank by SIR alone, you missed it. http://netdevops-tools.thebackroom.ai

    Post summary

    Cisco PSIRT released a bundle of advisories, highlighting a high‑severity Unity Connection RCE (CVE-2026-20034) and a medium‑severity ISE auth‑bypass (CVE-2026-20193).

    0000094
    499 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20193 A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain una… https://www.cve.org/CVERecord?id=CVE-2026-20193 ----- Traducción: CVE-2026-20193 Una vuln… http://infoflow.cloud`

    Post summary

    The tweet announces the disclosure of CVE‑2026‑20193, a Cisco ISE RADIUS Policy API flaw allowing read‑only administrators to acquire unauthorized access, but provides no PoC, exploit code, or patch details.

    0000039
    75 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine---
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--

Explore more