Executive brief
Cisco Identity Services Engine (ISE) is a network access and policy management platform used to authenticate and authorize users and devices. A SQL injection vulnerability in the SXP (Secure Group Tag Exchange Protocol) REST API allows authenticated administrators to view, modify, or delete database records. In single-node deployments, exploitation could cause complete service outage, blocking new endpoint access to the network until the system is restored.
Technical details
The vulnerability is a SQL injection flaw (CWE-641) in the SXP REST API resulting from insufficient input validation on REST API calls. An authenticated attacker with valid administrative credentials can exploit this by sending maliciously crafted input to an affected device. Successful exploitation allows the attacker to execute arbitrary SQL queries, viewing or modifying the underlying database. The attack requires network access to the ISE REST API, valid administrative credentials, the SXP service enabled, and at least one SXP connection configured. In single-node deployments, exploitation can cause denial of service, preventing unauthenticated endpoints from accessing the network. Cisco has released software patches to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine <UNKNOWN>
Timeline
- 2026-09-16: disclosed