SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-20300
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read or modify data in the underlying database.
The vulnerability exists due to improper input validation in Cisco Identity Services Engine when handling crafted requests. A remote user can send a crafted request to read or modify data in the underlying database.
Exploitation requires at least low-privileged administrative credentials.