SQL Injection Vulnerability in Cisco Identity Services Engine
CVE-2026-20300
7.1HIGH
What is CVE-2026-20300?
A SQL injection vulnerability in Cisco Identity Services Engine (ISE) can be exploited by an authenticated remote attacker with low-privileged administrative credentials. This vulnerability arises from inadequate validation of user-supplied input. By sending specially crafted requests to the vulnerable device, an attacker could potentially read or modify sensitive data stored in the underlying database, raising significant risks of data exposure and integrity compromise.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3