SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-20235

 

SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-20235

Published: September 17, 2026


Vulnerability identifier: #VU150729
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20235
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insufficient validation of user-supplied parameters in the Cisco Identity Services Engine API when handling API requests. A remote privileged user can send a crafted API request to disclose sensitive information.

Disclosed information may include hashed credentials that could be used in future attacks.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2026-20235

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

External References

Related Security Bulletins