ZeroHour

CVE-2026-20234

large

Critical credential-exposure flaw in Cisco ISE and ISE Passive Identity Connector

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20234 is a set of insufficiently protected credential issues (CWE-522) in Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC), discovered during Cisco's internal security review and fixed in a software hardening release. An attacker with low-privileged network access to the device can exploit the flaw without user interaction; the CVSS scope change (S:C) with high confidentiality, integrity, and availability impacts indicates the attacker can cross a security boundary and gain far more than their initial low-privilege foothold, plausibly by recovering protected credentials stored or managed by ISE. Any organization running Cisco ISE or ISE-PIC is in scope, since these platforms centrally handle network access control and identity data for the enterprise. Exploitation status is currently clean: the issue is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Apply Cisco's software hardening release for ISE and ISE-PIC as soon as practical, checking the official Cisco advisory for the exact fixed versions for your release train. Because the flaw centers on insufficiently protected credentials, rotate credentials that ISE stores or manages (including administrative and internal identity store passwords) after patching, and restrict low-privileged user access to the appliance. Review ISE audit and authentication logs for signs that a low-privilege account was used to access protected configuration or credential data.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
largeTens of thousands of enterprise deployments (ISE is Cisco's flagship network access control platform) — Cisco markets ISE as its most widely deployed NAC solution with a customer base in the tens of thousands, and ISE-PIC ships alongside ISE; most instances sit on internal networks rather than being internet-exposed, so the installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20234 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522.

Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.