CVE-2026-20327: Cisco Unified Intelligence Center SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs valid user credentials for the affected Cisco Unified Intelligence Center device and access to its web-based management interface. The issue does not describe unauthenticated exploitation.
What can a successful attacker access?
A successful blind SQL injection attack can allow the attacker to read contents of the affected device's internal database. The provided information does not indicate integrity or availability impact.
What should defenders review while remediation is pending?
Review accounts with access to the web-based management interface, because valid credentials are required for exploitation. Investigate crafted or unusual requests to that interface for potential SQL injection attempts.