Back

MEDIUM

Cisco Identity Services Engine Authentication Bypass Vulnerability

Published May 6, 2026

Description

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published May 6, 2026
Updated May 6, 2026
Reserved Oct 8, 2025
CISA Vulnrichment
Updated May 6, 2026
NVD
Status Analyzed
Modified Jul 1, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published May 6, 2026
Updated May 6, 2026
Exploited since n/a
EUVD-2026-27862