CVE Explorer
CVE-2026-20195
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device.
This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Cisco Identity Services Engine Software","vendor":"Cisco","versions":[{"status":"affected","version":"3.3.0"},{"status":"affected","version":"3.3 Patch 2"},{"status":"affected","version":"3.3 Patch 1"},{"status":"affected","version":"3.3 Patch 3"},{"status":"affected","version":"3.4.0"},{"status":"affected","version":"3.3 Patch 4"},{"status":"affected","version":"3.4 Patch 1"},{"status":"affected","version":"3.3 Patch 5"},{"status":"affected","version":"3.3 Patch 6"},{"status":"affected","version":"3.4 Patch 2"},{"status":"affected","version":"3.3 Patch 7"…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:44d7919877e33e4d79f3fd9b68ba2d80715f585cecf2e09a471b70cc65bf9ab0 · sha256:0654b26ebe26f0f8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:44d7919877e33e4d79f3fd9b68ba2d80715f585cecf2e09a471b70cc65bf9ab0 · sha256:0654b26ebe26f0f8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-204","description":"Observable Response Discrepancy","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:44d7919877e33e4d79f3fd9b68ba2d80715f585cecf2e09a471b70cc65bf9ab0 · sha256:0654b26ebe26f0f8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"cisco-sa-ise-unauth-bypass-uxjRXGpb","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:44d7919877e33e4d79f3fd9b68ba2d80715f585cecf2e09a471b70cc65bf9ab0 · sha256:0654b26ebe26f0f8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.