Executive brief
Cisco Identity Services Engine (ISE) is an access control and policy management system used to authenticate and authorize users and devices on corporate networks. A SQL injection vulnerability in its REST API allows authenticated administrators to inject malicious SQL code to read sensitive data from the session database. While authentication is required, exploitation could expose session information and user credentials stored in the database.
Technical details
The vulnerability exists in Cisco ISE and ISE-PIC REST APIs due to insufficient parameterization of SQL queries. Certain input parameters are concatenated directly into SQL clauses without proper escaping or prepared statements. An authenticated, remote attacker with valid administrative credentials can exploit this by sending a crafted HTTP request containing SQL injection payloads in affected parameters. A successful exploit allows reading arbitrary data from the session database. Patches are available; no workarounds exist.
Affected products
- Cisco Identity Services Engine Multiple versions affected
- Cisco ISE Passive Identity Connector Multiple versions affected
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published