CVE-2026-20194
Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.
In plain language
AI Act nowBusinesses using Cisco Identity Services Engine or its Passive Identity Connector should treat this critical flaw as urgent because public exploit code is available and no fix information has been published.
CVE-2026-20194 is a CVSS 9.1 incorrect resource-transfer vulnerability (CWE-669) in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector, with network access and high-privilege credentials required.
What to do now
- Check whether your organization runs Cisco Identity Services Engine or Cisco ISE Passive Identity Connector, including administrator-managed appliances.
- Restrict management access to trusted administrator networks and review privileged accounts while a fix is unavailable.
- Check Cisco's security advisory for CVE-2026-20194 regularly; Cisco has not published a fixed version or patch information yet.
- Ask your IT provider to review administrator activity and unexpected configuration changes on these systems.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20194 and every CVE in our database. Create a free account — no credit card required.
Create Free Account