Cisco disclosed a CVSS 9.9 set of insufficiently protected credentials flaws in Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC), found during an internal security review and fixed in a software hardening release.
What Is It
CVE-2026-20234 tracks multiple vulnerabilities in Cisco ISE and ISE-PIC that fall under CWE-522 (Insufficiently Protected Credentials). Cisco's ISE and ISE-PIC engineering teams identified the issues during a comprehensive internal security review, which produced a software hardening release addressing several internally discovered vulnerabilities grouped under this identifier.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That vector describes a network-reachable issue with low attack complexity requiring only low privileges and no user interaction. Scope is Changed: meaning impact extends beyond the vulnerable component; with high impact to confidentiality, integrity, and availability alike.
Why It Matters
ISE is an identity and access control platform, so credentials handled by it are high-value by definition. The combination in this vector is what drives the near-maximum score: a low-privileged account reachable over the network is enough, and the changed scope indicates compromise can reach resources beyond ISE itself.
NVD lists the record as "Awaiting Analysis" as of its last modification on 2026-09-16, so no independent severity analysis or enriched product data is available from that source yet. The Cisco advisory remains the authoritative description of affected versions and fixes.
What's Vulnerable
Cisco Identity Services Engine Software: affected versions span the 3.1 through 3.5 trains, including 3.1.0 and Patches 1–11, 3.2.0 and Patches 1–10, 3.3.0 and Patches 1–11, 3.4.0 and Patches 1–6, and 3.5.0 with Patches 1–3.
Cisco ISE Passive Identity Connector: versions 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0.
Patch Status
Cisco has published a software hardening release that remediates the vulnerabilities tracked here. Consult the Cisco security advisory (cisco-sa-hardening-ise-XU5EwX5T) for the specific fixed releases applicable to your deployment and upgrade accordingly. No workarounds are described in the supplied source material.
Sources
- Cisco Security Advisory; cisco-sa-hardening-ise-XU5EwX5T: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T
- NVD, CVE-2026-20234: https://nvd.nist.gov/vuln/detail/CVE-2026-20234