CVE-2026-20327
Received Received - Intake

Blind SQL Injection in Cisco Unified Intelligence Center

Vulnerability report for CVE-2026-20327, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
cisco unified_intelligence_center *
cisco unified_intelligence_center 12.6(2)_es08
cisco unified_intelligence_center 15.0(1)_su2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a blind SQL injection vulnerability in Cisco Unified Intelligence Center's web-based management interface. It allows an authenticated attacker to send crafted requests to read the internal database of the affected device due to insufficient input validation.

Detection Guidance

Detection requires monitoring for unusual SQL query patterns or unauthorized database access attempts in the web-based management interface logs of Cisco Unified Intelligence Center. Check for crafted requests or errors indicating SQL injection in the interface logs.

Impact Analysis

An attacker with valid credentials could exploit this to read sensitive data from the device's internal database, potentially exposing confidential information. The impact is limited to data exposure since the vulnerability does not allow modification or deletion of data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements such as GDPR or HIPAA. Organizations using affected Cisco Unified Intelligence Center versions should remediate it to maintain regulatory compliance.

Mitigation Strategies

Immediately upgrade Cisco Unified Intelligence Center to fixed versions 12.6(2) ES08 or 15.0(1) SU2. Ensure all user credentials are reviewed and unnecessary accounts are removed. Monitor for suspicious activity in the management interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20327. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart