Description
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to.  

This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators. 
Published: 2026-09-16
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The flaw resides in Cisco Identity Services Engine's web‑based management interface. Certain files lack proper authorization enforcement, allowing an authenticated attacker with administrative privileges to export user data. This export surface can reveal sensitive information, including passwords that are normally hidden from administrators, thereby violating confidentiality.

Affected Systems

The vulnerability affects Cisco Identity Services Engine Software. No specific affected version numbers are provided in the advisory, so all installations using the web‑based management interface should be considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 4.9 indicates a medium severity. The EPSS score of less than 1 % suggests low current exploit probability. The vulnerability requires authenticated access and administrative rights, limiting the attacker to users with such privileges. Because the attack vector is internal (authenticated remote), the risk is moderate but does not pose widespread automatic exploitation. The advisory does not list the issue in the CISA KEV catalog, further indicating limited known exploitation.

Generated by OpenCVE AI on September 18, 2026 at 00:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco ISE update that corrects the missing authorization check.
  • Re‑evaluate and enforce strict role‑based access controls so only authorized administrators can access the export functionality.
  • If an immediate update is unavailable, restrict network access to the ISE web interface and disable the export feature through configuration or firewall rules until the patch is deployed.

Generated by OpenCVE AI on September 18, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. &nbsp; This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the&nbsp;users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators.&nbsp;
Title ISE information disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-19T14:21:54.927Z

Reserved: 2025-10-08T11:59:15.361Z

Link: CVE-2026-20072

cve-icon Vulnrichment

Updated: 2026-09-19T14:17:51.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.223

Modified: 2026-09-19T15:16:59.380

Link: CVE-2026-20072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses