CVE-2026-20247: Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability
A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can exploit the vulnerability remotely without authentication or user interaction by sending a crafted request to an affected Cisco ISE device.
What is the expected impact of a successful exploit?
A successful SQL injection attack could allow an attacker to modify data in the underlying database. The provided information does not indicate confidentiality disclosure or service availability impact.