---
id: CVE-2026-20300
title: >-
  A vulnerability in Cisco ISE could allow an authenticated, remote attacker to
  conduct SQL injection attacks on an affected device
summary: "A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials.\r…"
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-89
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.1.0
  - identity_services_engine_software 3.1.0 p1
  - identity_services_engine_software 3.1.0 p3
  - identity_services_engine_software 3.1.0 p2
  - identity_services_engine_software 3.2.0
  - identity_services_engine_software 3.1.0 p4
  - identity_services_engine_software 3.1.0 p5
  - identity_services_engine_software 3.2.0 p1
  - identity_services_engine_software 3.1.0 p6
  - identity_services_engine_software 3.2.0 p2
  - identity_services_engine_software 3.1.0 p7
  - identity_services_engine_software 3.3.0
  - identity_services_engine_software 3.2.0 p3
  - identity_services_engine_software 3.2.0 p4
  - identity_services_engine_software 3.1.0 p8
  - identity_services_engine_software 3.2.0 p5
  - identity_services_engine_software 3.2.0 p6
  - identity_services_engine_software 3.1.0 p9
  - identity_services_engine_software 3.3 Patch 2
  - identity_services_engine_software 3.3 Patch 1
  - identity_services_engine_software 3.3 Patch 3
  - identity_services_engine_software 3.4.0
  - identity_services_engine_software 3.2.0 p7
  - identity_services_engine_software 3.3 Patch 4
  - identity_services_engine_software 3.4 Patch 1
  - identity_services_engine_software 3.1.0 p10
  - identity_services_engine_software 3.3 Patch 5
  - identity_services_engine_software 3.3 Patch 6
  - identity_services_engine_software 3.4 Patch 2
  - identity_services_engine_software 3.3 Patch 7
  - identity_services_engine_software 3.4 Patch 3
  - identity_services_engine_software 3.5.0
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.3 Patch 8
  - identity_services_engine_software 3.2 Patch 8
  - identity_services_engine_software 3.5 Patch 1
  - identity_services_engine_software 3.3 Patch 9
  - identity_services_engine_software 3.2 Patch 9
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.5 Patch 2
  - identity_services_engine_software 3.3 Patch 10
  - identity_services_engine_software 3.3 Patch 11
  - identity_services_engine_software 3.4 Patch 6
  - identity_services_engine_software 3.2 Patch 10
  - identity_services_engine_software 3.1.0 p72
  - identity_services_engine_software 3.1.0 p11
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:17:07.307'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20300'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T14:36:29.091647Z'
epss: 0.00292
epssPercentile: 0.19402
ingestedAt: '2026-09-16T16:37:52.183Z'
---

## Overview

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials.

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read or modify data in the underlying database.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ise-sql-inj-3QTKR947** · Cisco · affected: Cisco Identity Services Engine Software (46 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947)
