THREAT OPS › Threat News › [NVD] CVE-2026-20072 (MEDIUM 4.9) — A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to.
This vulnerability exists because ce
[NVD] CVE-2026-20072 (MEDIUM 4.9) — A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because ce
CVE-2026-20072 CVSS: 4.9 MEDIUM Published: 2026-09-16T21:17:07.223
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to.
This vulnerability exists because certain files lack proper authorization enforcement. A
Indicators of compromise
- CVE-2026-20072cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-20072