ZeroHour

CVE-2026-20284

large

Authenticated SQL Injection in Cisco ISE SXP REST API

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog.

What to do: Upgrade ISE nodes to the fixed release identified in Cisco's security advisory (not specified in the source data). As interim mitigation, restrict access to the ISE admin/REST API to trusted management networks, disable the SXP service on nodes that do not use it, and audit admin accounts for credential compromise. Monitor Cisco PSIRT for updated fixed-version guidance.

Affected
Cisco Identity Services Engine (ISE) — SXP REST API
Estimated exposure
large≈10,000–100,000 ISE nodes worldwide (subset of tens of thousands of enterprise ISE deployments that have SXP enabled) — Cisco ISE is a market-leading enterprise NAC platform with tens of thousands of deployments, typically deployed internally rather than internet-facing, and only nodes with the SXP service and at least one SXP connection enabled are exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.

Weakness
CWE-943
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.

CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.

BleepingComputer · 6h agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76423CVE-2026-20176+4 CVEs1· 1 read

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.