SQL Injection Vulnerability in Cisco Identity Services Engine
CVE-2026-20284

9.1CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20284?

A vulnerability exists in the SXP REST API of Cisco's Identity Services Engine (ISE) due to inadequate validation of user-supplied input. An authenticated, remote attacker with valid administrative credentials can exploit this vulnerability by sending crafted input to the REST API, potentially leading to unauthorized viewing or modification of data within the device's underlying database. In instances where the ISE is deployed in a single-node configuration, a successful exploit may also impair the availability of the ISE node, preventing unauthenticated endpoints from accessing the network until the issue is resolved. Attackers must ensure that the SXP service is enabled and at least one SXP connection is configured to fully exploit this weakness.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.