PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20284 Cisco CVE debrief

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.

Vendor
Cisco
Product
Cisco Identity Services Engine Software
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Network administrators, security teams, and IT personnel responsible for Cisco ISE systems should assess exposure and prioritize patching or mitigation to prevent potential SQL injection attacks and DoS conditions.

Why it matters

CVE-2026-20284 is a critical SQL injection vulnerability in Cisco ISE that requires immediate attention from network administrators and security teams to prevent potential data breaches and DoS conditions. The vulnerability can be exploited by an authenticated, remote attacker with valid administrative credentials, and its impact can be significant in single-node deployments.

  • Potential data tampering or unauthorized access to underlying database
  • Possible DoS condition in single-node deployments
  • Required verification of SXP service and connection configurations
  • Need for restricted access to administrative credentials

Technical summary

The vulnerability in the SXP REST API of Cisco ISE allows an authenticated, remote attacker to conduct SQL injection attacks due to insufficient validation of user-supplied input in REST API calls. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device, potentially causing a DoS condition in single-node deployments. The attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured to exploit this vulnerability.

Defensive priority

Network administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential SQL injection attacks and DoS conditions.

Recommended defensive actions

  • Patch or update Cisco ISE systems to prevent exploitation
  • Verify SXP service and connection configurations
  • Monitor for suspicious activity and potential DoS conditions
  • Restrict access to administrative credentials
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, its impact, and potential exploitation. However, the corpus does not establish versions, exploitation, impact, or remediation for specific systems, requiring verification from the supplied official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-20284 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-20284

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-20284 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20284

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.