CVE-2026-20300
largeAuthenticated SQL Injection in Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) contains a SQL injection flaw (CWE-89) caused by improper validation of user-supplied input. A remote attacker who already holds at least low-privileged administrative credentials can send a crafted request to an affected device to trigger the injection. A successful exploit allows the attacker to read or modify data in the underlying ISE database, with high integrity impact reflected in the CVSS 7.1 score (C:L/I:H/A:N). Any organization running Cisco ISE is potentially affected, although exploitation requires valid administrative credentials, so internet-wide opportunistic attacks are unlikely. The flaw is not in CISA KEV, no public proof-of-concept is known, and there are currently no confirmed reports of exploitation in the wild.
What to do: Check the Cisco PSIRT advisory for CVE-2026-20300 and upgrade ISE to the fixed release it specifies. Until patched, audit and rotate low-privileged administrative accounts, enforce least privilege and MFA on the ISE admin interface, and keep that interface off the internet. Review ISE logs for unexpected or malformed requests to administrative endpoints that could indicate exploitation attempts.
| Cisco Identity Services Engine (ISE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read or modify data in the underlying database.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.