Cisco Identity Services Engine User Account Enumeration Vulnerability

Vulnerability

A vulnerability exists in an identity management API endpoint of Cisco Identity Services Engine (ISE) that could allow an unauthenticated, remote attacker to enumerate valid user accounts on the affected device. This issue arises because the API endpoint returns error messages that can be used to differentiate between valid and invalid usernames. By sending a series of crafted requests and analyzing the responses, an attacker could compile a list of valid usernames on the system.

Impact

Exploitation of this vulnerability could lead to unauthorized enumeration of user accounts, allowing an attacker to gather valid usernames that could be used for further attacks, such as phishing or credential stuffing.

Remediation

Cisco has released software updates to address this vulnerability. Users should upgrade to version 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3. For versions 3.2 and earlier, users should migrate to a fixed release.

Added: May 6, 2026, 6:38 PM
Updated: May 6, 2026, 6:38 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
6.3
remediation
0.0
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.