CVE Tools

CVE-2026-20194

Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-669

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.

In plain language

AI Act now

Businesses using Cisco Identity Services Engine or its Passive Identity Connector should treat this critical flaw as urgent because public exploit code is available and no fix information has been published.

Executive summary

CVE-2026-20194 is a CVSS 9.1 incorrect resource-transfer vulnerability (CWE-669) in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector, with network access and high-privilege credentials required.

If affected, business impact
Full system compromiseIdentity-service disruptionSensitive data exposureUnauthorized configuration changes

What to do now

  1. Check whether your organization runs Cisco Identity Services Engine or Cisco ISE Passive Identity Connector, including administrator-managed appliances.
  2. Restrict management access to trusted administrator networks and review privileged accounts while a fix is unavailable.
  3. Check Cisco's security advisory for CVE-2026-20194 regularly; Cisco has not published a fixed version or patch information yet.
  4. Ask your IT provider to review administrator activity and unexpected configuration changes on these systems.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20194 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows