SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-20235
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficient validation of user-supplied parameters in the Cisco Identity Services Engine API when handling API requests. A remote privileged user can send a crafted API request to disclose sensitive information.
Disclosed information may include hashed credentials that could be used in future attacks.