Executive brief
Cisco Identity Services Engine (ISE) is an enterprise platform for network authentication and access control. A critical SQL injection flaw allows unauthenticated remote attackers to modify sensitive data stored in the ISE database, potentially compromising user identities, network access policies, and authentication records.
Technical details
This is a SQL injection vulnerability (CWE-89) in Cisco ISE caused by improper validation of user-supplied input. The vulnerability is unauthenticated and remotely exploitable over the network with no special prerequisites. An attacker sends a crafted request containing SQL commands to bypass input validation, allowing them to execute arbitrary SQL queries and modify data in the underlying database, such as administrative credentials, policies, or audit logs. Cisco has released patched versions: ISE 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4, and customers on 3.2 or earlier must migrate to a fixed release.
Affected products
- Cisco Identity Services Engine 3.2 and earlier, 3.3 before Patch 12, 3.4 before Patch 7, 3.5 before Patch 4
Timeline
- 2026-09-16: disclosed