Skip to content

CVE-2026-20284 CVE-2026-20283 CVE-2026-20282

Cisco ISE SQL injection, command injection, and OS write access in APIs (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284)

Critical 9.1 Vendor: Cisco Published

Three authenticated vulnerabilities affect Cisco Identity Services Engine: SQL injection in the SXP REST API, command injection in the IPsec Open API, and write access through crafted HTTP. Cisco has fixes; a workaround exists for the IPsec API flaw.

What happened

Three vulnerabilities in Cisco Identity Services Engine are addressed in Cisco advisory cisco-sa-ise-mult-vul-ymSsTLCc. All three are reachable over the network and require valid administrative credentials.

CVE-2026-20284 is a SQL injection vulnerability in the SXP REST API. An attacker with administrative credentials, SXP enabled and at least one SXP connection configured can send crafted input to view or modify the underlying database. In a single-node deployment, exploitation can make the node unavailable, so endpoints that have not already authenticated would be unable to access the network until the node is restored.

CVE-2026-20283 is a command injection vulnerability in the IPsec Open API. With administrative credentials, on a node with more than one network interface and one configured active IPsec tunnel, an attacker can execute arbitrary commands on the underlying operating system. CVE-2026-20282 lets an authenticated administrative attacker send a crafted HTTP request to obtain write access to the underlying operating system. Cisco notes that for these two vulnerabilities it assigned a High Security Impact Rating rather than Medium because it is easy to reach root from the achieved privilege level. Cisco PSIRT is aware of a public announcement but is not aware of any malicious use. CVE-2026-20284 has a CVSS 3.1 score of 9.1; CVE-2026-20283 and CVE-2026-20282 have scores of 6.5 and 4.9 respectively.

Who is affected

Cisco Identity Services Engine Software is affected. CVE-2026-20284 and CVE-2026-20282 affect versions 3.1.0, 3.1.0 p1 through p5, 3.2.0 and 3.2.0 p1. CVE-2026-20283 affects 3.3.0, 3.3 Patch 1 through Patch 5, 3.4.0 and 3.4 Patch 1. In the single-node DoS condition described for CVE-2026-20284, endpoints that have not already authenticated would be unable to access the network until the node is restored.

What to do now

  1. Apply Cisco's fixed release. Cisco has made fixes available, but the specific fixed version numbers are not listed in this page's version data; refer to the Cisco advisory linked from this page to identify the correct release for your current version.
  2. For CVE-2026-20283 only, if an IPsec VTI tunnel was created using the API, use the workaround: in the Cisco ISE web interface go to Administration > System > Settings > Protocols > IPsec > Native IPsec, remove the tunnel with the vulnerable configuration, then add it back using the web interface. Cisco states the web interface does not allow the vulnerable configuration.
  3. For CVE-2026-20282 and CVE-2026-20284, no workaround is available; patching is the only direct remediation.
  4. Until patched, restrict access to the ISE management and API interfaces to trusted administrative networks and review administrative account activity for unexpected changes.

How to detect it

The advisory data supplied here does not list indicators of compromise. Because all three vulnerabilities require valid administrative credentials, review administrative logins and configuration changes for unexpected activity. In particular, check for IPsec VTI tunnels created through the API rather than the web interface, and watch for a single-node ISE becoming unavailable with endpoints unable to authenticate. An outage is a possible consequence of CVE-2026-20284, not proof of exploitation.

Beyond the patch

Beyond the patch, this is third-party risk in the network access control layer: Cisco ISE sits in the authentication path, so database or operating-system compromise has consequences across the estate. Supply Chain Defense & Third-Party Risk is the service for tracking and assessing vendor software like this in your environment. If you need help prioritising remediation, book a meeting.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20284
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20283
Cisco Identity Services Engine Software
3.3.0
3.3 Patch 2
3.3 Patch 1
3.3 Patch 3
3.4.0
3.3 Patch 4
3.4 Patch 1
3.3 Patch 5
No fixed version listed yet
CVE-2026-20282
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.