ZeroHour

CVE-2026-20247

large

Unauthenticated SQL Injection in Cisco Identity Services Engine (ISE)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Cisco Identity Services Engine (ISE) contains a SQL injection vulnerability (CWE-89) caused by improper validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to an affected device, requiring no credentials or user interaction. A successful exploit allows the attacker to modify data in the underlying ISE database; Cisco's CVSS scoring (C:N/I:H/A:N) frames this as an integrity-only impact, with no confidentiality or availability loss. Any organization running Cisco ISE is affected, though the device is typically deployed on internal networks rather than exposed to the internet. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Check Cisco's security advisory for CVE-2026-20247 and upgrade ISE to the fixed release it specifies for your deployment. Until patching, restrict network access to ISE web-based interfaces (admin and portal) to trusted management networks and monitor for unexpected database changes. Confirm your ISE node inventory, since distributed deployments mean every node in the cluster must be remediated.

Affected
Cisco Identity Services Engine (ISE)
Estimated exposure
large≈10,000–100,000 ISE systems worldwide (multi-node enterprise clusters; far fewer internet-exposed) — Cisco ISE is one of the most widely deployed network access control products across enterprise, education, and government networks, and customers typically run it as multi-node clusters, so total installed systems plausibly reach the tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.