Description
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Published: 2026-09-16
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

A vulnerability in the Cisco Identity Services Engine API allows an authenticated, remote attacker to retrieve sensitive data from an affected device. The flaw arises from insufficient validation of user-supplied parameters, enabling the attacker to send crafted API requests that return confidential information such as hashed credentials that could be leveraged for future attacks. The primary impact is the exposure of confidential data without compromising the system’s control or integrity.

Affected Systems

The affected product is Cisco Identity Services Engine Software. No specific version range is listed; the vulnerability applies to all installations that have not applied the vendor’s fix.

Risk and Exploitability

The CVSS score of 4.9 indicates medium severity, and the EPSS score of less than 1% denotes a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated remote attacker who can send API requests with valid administrative credentials. Successful exploitation would grant access to sensitive information, increasing the risk of credential theft and subsequent compromise of other network resources.

Generated by OpenCVE AI on September 18, 2026 at 00:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco ISE patch that addresses the information disclosure flaw
  • Restrict API access to trusted administrators and use network segmentation to limit exposure
  • Enforce strong authentication mechanisms and monitor API usage for anomalous activity

Generated by OpenCVE AI on September 18, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Title Cisco Identity Services Engine Information Disclosure Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-22T20:29:44.973Z

Reserved: 2025-10-08T11:59:15.400Z

Link: CVE-2026-20235

cve-icon Vulnrichment

Updated: 2026-09-22T20:24:48.631Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:08.060

Modified: 2026-09-22T21:17:30.283

Link: CVE-2026-20235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')