Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities
Cisco fixed ISE vulnerabilities enabling authenticated SQL injection and OS command execution; CVE-2026-20282 and CVE-2026-20283 rated High.
Multiple Cisco Identity Services Engine vulnerabilities allow an authenticated remote attacker to conduct SQL injection, modify data, or execute arbitrary commands on the underlying OS. Cisco assigned a Security Impact Rating of High to CVE-2026-20282 and CVE-2026-20283 because attackers can easily reach root from the achieved privilege level. Software updates are available and a workaround addresses one of the vulnerabilities.
45