Description
A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks.

This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Database compromise leading to data exposure or denial of service
Action: Immediate patch
AI Analysis

Impact

A SQL injection flaw exists in the SXP REST API of Cisco Identity Services Engine that stems from inadequate validation of user input. An attacker who possesses valid administrative credentials can send crafted API requests that are executed directly against the underlying database. Successful exploitation enables the attacker to read confidential data or modify records, and it can also lead to service disruption; in single‑node deployments the ISE node may become unavailable, causing a denial of service for unauthenticated endpoints until the node is restored.

Affected Systems

The vulnerability affects Cisco Identity Services Engine Software that exposes the SXP REST API, particularly when the SXP service is enabled and at least one SXP connection is configured. Specific version information is not supplied in the advisory.

Risk and Exploitability

The CVSS score of 9.1 reflects the high severity of this flaw, while the EPSS score of less than 1% indicates a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access with administrative rights, making the threat contingent upon credential compromise or insider actions. If an attacker gains such access, the impact could be significant, but the overall risk remains moderated by the credential requirement.

Generated by OpenCVE AI on September 18, 2026 at 00:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cisco Identity Services Engine to a version that contains the fix for the SXP REST API SQL injection flaw.
  • If a patch is not yet available, disable the SXP service or restrict SXP connections to trusted devices.
  • Continuously monitor ISE logs for unusual SQL queries or failed authentication attempts to identify potential abuse of the REST API.

Generated by OpenCVE AI on September 18, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.
Title Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:55:33.732Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20284

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:46.528Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:09.090

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:31:09Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic