SQL Injection Vulnerability in Cisco Identity Services Engine
CVE-2026-20247
7.5HIGH
What is CVE-2026-20247?
A SQL injection vulnerability exists in Cisco Identity Services Engine (ISE) due to inadequate validation of user input. This flaw allows unauthenticated, remote attackers to send specially crafted requests, potentially enabling them to manipulate data stored in the database. Exploitation of this vulnerability can lead to unauthorized access and significant data integrity issues. It is essential for organizations using affected versions of Cisco ISE to apply the necessary patches promptly.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3