Skip to main content
Vulnerability Database/CVE-2026-20284

CVE-2026-20284: Cisco ISE SXP REST API SQL Injection

CVE-2026-20284 is a SQL injection flaw in Cisco Identity Services Engine SXP REST API that lets authenticated attackers view or modify database data. This article covers technical details, affected versions, and mitigation strategies.

Updated:

CVE-2026-20284 Overview

Cisco Identity Services Engine (ISE) contains a SQL injection vulnerability in the Security Group Tag Exchange Protocol (SXP) REST API. The flaw stems from insufficient validation of user-supplied input in REST API calls. An authenticated remote attacker with valid administrative credentials can send crafted input to view or modify data in the underlying database.

Critical Impact

Successful exploitation allows database read and write access. In single-node deployments, the affected ISE node can become unavailable, creating a denial-of-service condition that blocks unauthenticated endpoints from accessing the network.

Affected Products

  • Cisco Identity Services Engine (ISE) with the SXP service enabled
  • Cisco ISE deployments with at least one SXP connection configured
  • Cisco ISE single-node and multi-node deployments exposing the SXP REST API

Discovery Timeline

  • 2026-09-16 - CVE-2026-20284 published to NVD
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-20284

Vulnerability Analysis

The vulnerability resides in the SXP REST API component of Cisco ISE. The API fails to properly validate and sanitize user-supplied parameters before incorporating them into database queries. This maps to [CWE-943] Improper Neutralization of Special Elements in Data Query Logic.

An attacker with administrative credentials can inject crafted SQL fragments through REST API calls. The injected statements execute against the underlying ISE database with the privileges of the API service. This exposes stored policy data, endpoint identities, and configuration records to unauthorized read and write operations.

The impact extends beyond data compromise. In single-node deployments, exploitation can render the ISE node unresponsive. Endpoints that have not previously authenticated cannot reach the network until administrators restore the node.

Root Cause

The root cause is missing input sanitization on parameters accepted by the SXP REST API endpoints. Cisco ISE constructs database queries by concatenating attacker-controlled values without parameterized statements or safe escaping routines.

Attack Vector

Exploitation requires three preconditions. The attacker must hold valid administrative credentials, the SXP service must be enabled, and at least one SXP connection must be configured. Given these conditions, the attacker sends crafted HTTP requests to the SXP REST API over the network. The scope change reflected in the CVSS vector indicates that impact extends beyond the vulnerable component to the underlying database subsystem.

No verified proof-of-concept code is publicly available. Refer to the Cisco Security Advisory for authoritative technical details.

Detection Methods for CVE-2026-20284

Indicators of Compromise

  • Unexpected SQL syntax, quotes, comment markers (--, /*), or UNION keywords in SXP REST API request bodies or query parameters
  • Administrative API calls to SXP endpoints originating from unusual source addresses or outside normal change windows
  • Database errors, stack traces, or anomalous query latency correlated with SXP REST API traffic
  • Sudden unavailability of an ISE node accompanied by prior authenticated SXP REST API activity

Detection Strategies

  • Inspect ISE application logs and REST API access logs for malformed SXP requests and repeated 4xx/5xx responses from SXP endpoints
  • Correlate administrative authentication events with subsequent SXP REST API calls to identify credential misuse
  • Deploy WAF or API gateway rules that flag SQL metacharacters in parameters bound for the SXP REST API

Monitoring Recommendations

  • Forward Cisco ISE syslog, REST API audit logs, and administrative activity to a centralized SIEM for correlation
  • Alert on newly created or modified SXP connections and on privilege changes to ISE administrative accounts
  • Monitor ISE node health metrics to identify DoS conditions that align with SXP REST API activity

How to Mitigate CVE-2026-20284

Immediate Actions Required

  • Apply the fixed Cisco ISE release identified in the Cisco Security Advisory
  • Rotate ISE administrative credentials and audit all accounts with SXP configuration privileges
  • Restrict network access to ISE administrative and REST API interfaces to trusted management networks only
  • Review SXP connection configurations and remove any that are unused

Patch Information

Cisco has published a security advisory tracking this issue. Administrators should consult the Cisco Security Advisory cisco-sa-ise-mult-vul-ymSsTLCc for fixed software versions, upgrade guidance, and any additional advisories that address related ISE vulnerabilities.

Workarounds

  • Disable the SXP service on ISE nodes where it is not operationally required
  • Remove SXP connection configurations if SXP functionality is not in use, since at least one configured connection is required for exploitation
  • Enforce multi-factor authentication and least-privilege role assignments for all ISE administrative accounts to reduce the risk of credential compromise
bash
# Configuration example
# Consult Cisco ISE documentation for the exact CLI or admin UI steps to disable SXP.
# From the ISE administrative interface: Work Centers > TrustSec > SXP > Disable service
# Restrict management plane access at the network layer:
# access-list ISE_MGMT permit tcp <trusted-mgmt-subnet> host <ise-node-ip> eq 443
# access-list ISE_MGMT deny   tcp any host <ise-node-ip> eq 443

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.