Summary
CVE-2026-20192 is a critical improper access control vulnerability (CWE-284) in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw allows an unauthenticated, remote attacker to bypass authorization checks over the network with no user interaction, potentially compromising confidentiality, integrity, and availability of the affected system. The issue was discovered internally by Cisco during a proactive security review and carries the maximum CVSS v3.1 base score of 10.0.
Technical details
- Root cause: Improper access control (CWE-284) within Cisco ISE/ISE-PIC that fails to correctly enforce authorization, authentication, and privilege boundaries in certain request-handling paths.
- Trigger conditions: An attacker sends specially crafted requests to an affected ISE/ISE-PIC deployment; no credentials, prior access, or user interaction are required.
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), with a changed scope (S:C) — meaning impact can extend beyond the vulnerable component itself.
- Impact: High impact to confidentiality, integrity, and availability (C:H/I:H/A:H), consistent with a full authorization/access-control bypass on a critical network access control and identity platform.
- Discovery: Identified by Cisco during internal security testing (using established testing processes alongside newer testing methods) rather than through external or in-the-wild discovery. Cisco PSIRT states it is not aware of any public exploit code or malicious use at the time of disclosure.
Affected software
- Cisco Identity Services Engine (ISE) Software: releases 3.1.0 through 3.5.0, including all associated patch levels (e.g., 3.1.0 through Patch 11, 3.2.0 through Patch 10, 3.3.0 through Patch 11, 3.4.0 through Patch 6, 3.5.0 through Patch 3)
- Cisco ISE Passive Identity Connector (ISE-PIC): releases 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to the fixed releases published by Cisco:
- ISE 3.1 → Patch 12
- ISE 3.2 → Patch 11
- ISE 3.3 → Patch 12
- ISE 3.4 → Patch 7
- ISE 3.5 → Patch 4
- If no patch can be applied immediately: Cisco states there are no workarounds that address this vulnerability. Organizations unable to patch immediately should restrict network access to ISE/ISE-PIC administrative and service interfaces to trusted management networks only, and closely monitor ISE logs for anomalous authentication or authorization activity until patching is completed.
- Review Cisco’s advisory for any additional vulnerabilities addressed in the same hardening release, as multiple related CVEs were disclosed alongside CVE-2026-20192.

