External risk intelligence

Cisco ISE SXP REST API SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-20284

The vulnerability affects the REST API of Cisco ISE, which is a network-accessible interface. While REST APIs can be exposed, this specific interface requires valid administrative credentials and specific service configurations (SXP enabled with at least one connection), making widespread public internet exposure less common than standard web gateways.

SQL Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts Cisco's Identity Services Engine (ISE) REST API, a component used for network access control. It allows an authenticated attacker with administrative privileges to potentially inject malicious SQL commands, which could lead to unauthorized access, modification, or deletion of sensitive data. In some configurations, exploitation could also disrupt service availability, preventing new endpoints from accessing the network.

  • Attackers can manipulate data and disrupt service.
  • Requires admin access, limiting broad impact.
  • Confirm if ISE is deployed and if SXP is enabled.

Attack Path

How an attacker could exploit the issue

An attacker with administrative access to Cisco ISE could exploit this SQL injection vulnerability by sending specially crafted input through the SXP REST API. This could allow them to view or alter data in the device's database. In single-node setups, this could also lead to a denial-of-service condition, preventing new endpoints from accessing the network until the system is restored.

  • Requires administrative credentials and SXP configuration.
  • Triggered by crafted input to SXP REST API.
  • Risk of data compromise, modification, or denial of service.

Live Threat

Current exploitation, exposure, and threat context

An authenticated attacker with administrative credentials could exploit this vulnerability to conduct SQL injection attacks against the Cisco ISE SXP REST API. This could lead to viewing or modifying data within the underlying database. In single-node deployments, successful exploitation might also cause a denial-of-service condition, preventing unauthenticated endpoints from accessing the network until the node is restored.

  • System database.
  • Crafted API input.
  • Data exposure or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Cisco Identity Services Engine (ISE) SXP REST API vulnerability requires action from teams responsible for the application and its underlying infrastructure, likely application owners and infrastructure or platform teams. The first step is to identify all deployed ISE instances, confirm their exposure and criticality, and then determine the responsible owner for remediation planning.

  • Application owners should coordinate remediation.
  • Verify SXP service and administrative access.
  • Plan remediation based on exposure and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cisco ISE and its SXP REST API?

Cisco Identity Services Engine (ISE) is a platform that manages network access control, helping organizations securely connect users and devices. The SXP (Scalable Group Tag Exchange Protocol) REST API is a specific interface within ISE used to automate or manage SXP-related configurations. It acts as a programmatic bridge allowing authorized systems to communicate with the ISE node to maintain network segmentation and policy enforcement.

What does SQL injection mean for CVE-2026-20284?

This vulnerability is classified as CWE-943, which involves improper neutralization of special elements in database queries. In simple terms, the API does not properly check input provided by users. An attacker can input malicious commands that the underlying database executes as if they were legitimate instructions, potentially allowing unauthorized viewing or changing of stored data.

How is the SXP REST API vulnerability triggered?

An attacker must send crafted input to the affected API to trigger the flaw. Importantly, it is not triggered by public traffic alone; the attacker must already possess valid administrative credentials for the system. Additionally, the vulnerability remains dormant if the SXP service is disabled or if no SXP connections are configured, as the specific code path containing the flaw would not be active.

Is my Cisco ISE deployment at risk?

Halo Surface Signal indicates this vulnerability involves a network-accessible interface, but the risk is moderated by strict requirements. Because the exploit demands administrative-level access and specific service configurations, it is less likely to be vulnerable than a simple web gateway. You should prioritize assessment if your ISE instance is network-reachable and has SXP features actively enabled.

What should I do to respond to this vulnerability?

Begin by auditing your infrastructure to confirm where Cisco ISE is deployed and identify which instances have the SXP service enabled. Once identified, verify which teams manage these specific nodes and coordinate with them to review access logs. Since the flaw requires administrative credentials, ensuring robust access control and monitoring for unauthorized administrative activity is a vital protective measure.

References