Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3665 articles · 153552 vulns · 36/41 feeds (7d)
← Back to list
4.3
CVE-2026-20193
Cisco · Cisco Identity Services Engine Software

Cisco Identity Services Engine Authentication Bypass Vulnerability

Description

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.3.0, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.3 Patch 4, 3.4 Patch 1, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisidentity services engine (ise)cert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb

Related News (2 articles)

Tier B
BSI Advisories7d ago
[NEU] [mittel] Cisco Identity Services Engine (ISE): Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB8d ago
CVE-2026-20193 | Cisco Identity Services Engine Software 3.3.0/3.4.0/3.5.0 RADIUS Policy API Endpoint authorization (cisco-sa-ise-unauth-bypass-uxjRXGpb)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-862
PublishedMay 6, 2026
Last enriched8d ago
Trending Score13
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20182EXPKEV
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Trending: 152
HIGHCVE-2026-20185
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
Trending: 16
HIGHCVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Trending: 14
MEDIUMCVE-2026-20189
Cisco Prime Infrastructure Information Disclosure Vulnerability
Trending: 13
MEDIUMCVE-2026-20169
Cisco IoT Field Network Director Command Injection Vulnerability
Trending: 12

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026