SQL Injection Vulnerability in Cisco Identity Services Engine
CVE-2026-20247

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20247?

A SQL injection vulnerability exists in Cisco Identity Services Engine (ISE) due to inadequate validation of user input. This flaw allows unauthenticated, remote attackers to send specially crafted requests, potentially enabling them to manipulate data stored in the database. Exploitation of this vulnerability can lead to unauthorized access and significant data integrity issues. It is essential for organizations using affected versions of Cisco ISE to apply the necessary patches promptly.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.