CVE-2026-20195
Cisco Identity Services Engine ≤ 3.2.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSummary
CVE-2026-20195 is a medium-severity Observable Response Discrepancy (CWE-204) vulnerability in Cisco Identity Services Engine. Its CVSS base score is 5.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked at the 20th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-11 (Error Handling) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-27863
Vulnerability Data
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is…
more
called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of valid usernames on an affected system.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Direct account enumeration via API response discrepancy enables T1087 and sub-techniques for local/domain accounts.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires that error messages from the ISE API not reveal whether a username is valid, eliminating the observable response discrepancy exploited by CVE-2026-20195.
Enforces that the identity-management endpoint must not disclose account existence to unauthenticated callers, blocking the enumeration technique at the access decision point.
Enables monitoring of high-volume crafted requests to the ISE API, allowing detection of active username enumeration attempts described in the CVE.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent introduction of inconsistent response behavior that leaks internal state.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect observable response discrepancies before deployment.
Network security controls can enforce uniform responses and suppress observable discrepancies.
Secure SDLC practices include error-handling and response standardization to avoid information disclosure.
Application security requirements typically mandate consistent, non-revealing error messages.
Secure architecture principles discourage designs that leak internal state via differing responses.
Secure coding standards explicitly require uniform error handling to prevent information leakage.