Executive brief
Cisco Identity Services Engine (ISE) is used to manage network identity and access policies. An authenticated attacker with administrative credentials can inject malicious SQL commands to read or modify the underlying database, potentially exposing or altering sensitive network access control and user identity data.
Technical details
This is a SQL injection vulnerability (CWE-89) in Cisco ISE caused by improper validation of user-supplied input. The vulnerability requires the attacker to have at least low-privileged administrative credentials and can be exploited via a crafted network request without user interaction. A successful exploit allows the attacker to read or modify data in the underlying database. Cisco has released patched software versions (3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4, and later releases) that address this vulnerability. The advisory indicates no workarounds are available.
Affected products
- Cisco Identity Services Engine 3.2 and earlier, 3.3 before Patch 12, 3.4 before Patch 7, 3.5 before Patch 4
Timeline
- 2026-09-16: disclosed