Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Check for Update
AI Analysis

Impact

The flaw involves incorrect transfer of resources between logical spheres within Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE‑PIC). This may allow an attacker to move data into an unauthorized sphere, potentially exposing confidential information or enabling privilege escalation because access controls are improperly enforced.

Affected Systems

The affected products are Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. The advisory does not list specific versions, so any deployment of these products that has not yet applied the hardening release could be vulnerable. The risk applies to both the core ISE appliance and the connected passive identity connector component.

Risk and Exploitability

The CVSS score of 9.1 indicates a severe threat, while the EPSS score of less than 1% suggests that exploitation is presently rare. The vulnerability is not in the CISA KEV catalog. Likely exploitation would require an authenticated session with sufficient privileges on the ISE environment; an attacker would need to trigger the improper resource transfer, possibly by manipulating configuration or exploiting a feature that moves resources between spheres. The lack of an official fix in the advisory means that vendors must be monitored for a future hardening release or patch.

Generated by OpenCVE AI on September 18, 2026 at 00:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Visit Cisco’s security advisory page and check for a hardening release that addresses CVE‑2026‑20194; if one becomes available, plan to deploy it as soon as possible.
  • Until a vendor‑issued fix is released, review and tighten sphere configuration to ensure that resource transfers are authorized and properly validated; consider denying cross‑sphere movement unless explicitly required.
  • Enable detailed logging for resource transfer events and monitor these logs for anomalous activity that could indicate an exploit attempt.

Generated by OpenCVE AI on September 18, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.
Title Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:55:48.071Z

Reserved: 2025-10-08T11:59:15.396Z

Link: CVE-2026-20194

cve-icon Vulnrichment

Updated: 2026-09-17T16:05:46.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:22.047

Modified: 2026-09-18T04:17:33.583

Link: CVE-2026-20194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:42Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres