← Back

CVE-2026-20193

nvd nist
Published: May 6, 2026Modified: Jul 1, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.

Affected (21)

1 product
Identity Services Engine
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 3.2.0
Version 3.3.0
Version 3.3.0 patch10
Version 3.3.0 patch1
Version 3.3.0 patch2
Version 3.3.0 patch3
Version 3.3.0 patch4
Version 3.3.0 patch5
Version 3.3.0 patch6
Version 3.3.0 patch7
Version 3.3.0 patch8
Version 3.3.0 patch9
Version 3.4.0
Version 3.4.0 patch1
Version 3.4.0 patch2
Version 3.4.0 patch3
Version 3.4.0 patch4
Version 3.4.0 patch5
Version 3.5.0
Version 3.5.0 patch1
Version 3.5.0 patch2

Timeline

No history available yet.