medium · CVSS v3 4.9
CVE-2026-20072
A flaw in Cisco ISE’s web management interface lets an authenticated admin export user data from outside their security group, revealing pas
Overview
A flaw in Cisco ISE’s web management interface lets an authenticated admin export user data from outside their security group, revealing passwords that should be hidden. The issue stems from missing authorization checks on export endpoints.
Description
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators.
Impact
{'confidentiality': 'Unauthorized disclosure of user passwords and other sensitive account data.', 'integrity': 'No direct impact on data integrity.', 'availability': 'No impact on service availability.'}
Remediation
['Apply the latest Cisco ISE security patch or upgrade to the most recent release.', 'Review and tighten administrative roles; enforce least‑privilege for user‑export functions.', 'Disable or restrict the export feature for users who do not need it.', 'Verify that authorization checks are in place for all user‑data endpoints.', 'Monitor audit logs for anomalous export activity and conduct regular privilege reviews.']
Risk context
The vulnerability has a CVSS v3 score of 4.9 (medium). While it does not affect availability, it allows privileged attackers to read passwords of users outside their group, posing a moderate confidentiality risk. Prompt patching and privilege hardening are recommended.
Affected products
- Cisco Identity Services Engine (ISE)
- Cisco ISE web interface
Scores
- Severity
- medium
- CVSS v2
- 6.1
- CVSS v3
- 4.9
- CVSS v4
- —
- EPSS
- —