CVE-2026-20247
largeUnauthenticated SQL Injection in Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) contains a SQL injection vulnerability (CWE-89) caused by improper validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to an affected device, requiring no credentials or user interaction. A successful exploit allows the attacker to modify data in the underlying ISE database; Cisco's CVSS scoring (C:N/I:H/A:N) frames this as an integrity-only impact, with no confidentiality or availability loss. Any organization running Cisco ISE is affected, though the device is typically deployed on internal networks rather than exposed to the internet. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Check Cisco's security advisory for CVE-2026-20247 and upgrade ISE to the fixed release it specifies for your deployment. Until patching, restrict network access to ISE web-based interfaces (admin and portal) to trusted management networks and monitor for unexpected database changes. Confirm your ISE node inventory, since distributed deployments mean every node in the cluster must be remediated.
| Cisco Identity Services Engine (ISE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.