Executive brief
Cisco Identity Services Engine (ISE) is a network access control and identity management platform used to authenticate and authorize users and devices. A SQL injection vulnerability in ISE's APIs allows authenticated administrators to execute arbitrary database queries, potentially exposing sensitive identity and configuration data stored in the backend database and facilitating lateral movement or data theft.
Technical details
This vulnerability is a SQL injection flaw (CWE-89) in Cisco ISE APIs caused by insufficient validation of parameters that are directly concatenated into SQL queries. An authenticated attacker with valid administrative credentials can send a crafted request containing SQL statements to a vulnerable API endpoint to read arbitrary data from the backend database and conduct server-side request forgery (SSRF) attacks. The vulnerability requires authentication and network access to the ISE REST API port. Cisco has released software updates to address this issue; no workarounds are available.
Affected products
- Cisco Identity Services Engine
Timeline
- 2026-09-16: disclosed