Authenticated Blind SQL Injection in Cisco Unified Intelligence Center Web Interface
AI analysis
Cisco Unified Intelligence Center contains a blind SQL injection flaw (CWE-89) in its web-based management interface, caused by insufficient validation of user-supplied input. To trigger it, an attacker who already holds valid user credentials on the affected device sends a crafted request to the management interface. A successful exploit lets the attacker read the contents of the device's internal database, with no impact on integrity or availability. Any organization running Cisco Unified Intelligence Center is exposed, though the requirement for valid, low-privileged credentials raises the bar for exploitation. As of publication there is no known exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%.
What to do: Check whether Cisco Unified Intelligence Center is deployed in your environment and apply the fix released with Cisco's August 19, 2026 advisories, consulting the official advisory for the affected and fixed release lists. Until patched, restrict access to the web-based management interface to trusted management networks and limit which accounts hold valid credentials on the device. Monitor authentication logs for low-privileged accounts querying the management interface, since exploitation requires valid credentials.
Affected
| Cisco Unified Intelligence Center (web-based management interface) | — |
Estimated exposure
largetens of thousands of enterprise deployments — Cisco Unified Intelligence Center is typically deployed as part of enterprise Cisco unified communications/contact-center environments whose on-premises installed base is substantial, but it is an internal management interface rather than…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.