Security Advisory Desk
mediumQCS priority 76/100Cisco

Cisco Unified Intelligence Center SQL Injection Vulnerability

A security weakness was found in the web management interface of Cisco Unified Intelligence Center. An attacker who already has authorized access could exploit this flaw to run hidden database commands and see sensitive data stored inside the device. Cisco has released updates to fix this issue, and there are no other workarounds to prevent this risk.

Published 19/8/2026, 4:00:00 pmVerified 19/8/2026, 7:21:55 pmRevision 1
Cisco medium network security advisory visual

In plain language

What this advisory means

A security weakness was found in the web management interface of Cisco Unified Intelligence Center. An attacker who already has authorized access could exploit this flaw to run hidden database commands and see sensitive data stored inside the device. Cisco has released updates to fix this issue, and there are no other workarounds to prevent this risk.

Technical explanation

How the issue affects the environment

The vulnerability resides in insufficient validation of user inputs in the web-based management interface of Cisco Unified Intelligence Center. This flaw allows an authenticated local attacker to conduct a blind SQL injection attack by sending specially crafted requests. Successful exploitation could disclose contents of the internal device database. Exploitation requires valid user credentials. Cisco assigned this vulnerability CVE-2026-20327 with a CVSS base score of 6.5 (medium severity). Cisco has provided fixed software releases starting with versions 12.6(2) ES08 and 15.0(1) SU2. There are no viable workarounds; upgrading to patched software is necessary to remediate the issue.

Operational impact

Why teams should care

An attacker with legitimate access to the Cisco Unified Intelligence Center system could gain unauthorized visibility into sensitive internal data through this SQL injection vulnerability. Exposure of confidential or operational information can lead to data breaches and potential compromise of system integrity. Organizations should prioritize updating affected systems to maintain confidentiality and protect business data.

Immediate action

Cisco strongly recommends upgrading Cisco Unified Intelligence Center to software versions 12.6(2) ES08, 15.0(1) SU2, or later to fully remediate the SQL injection vulnerability. Customers should access Cisco’s software download portals or contact Cisco Technical Assistance Center for upgrade assistance.

Affected and fixed releases

Affected versionsEarlier than 12.6
Fixed versions12.6(2) ES08, 15.0(1) SU2

Temporary risk reduction

Cisco states there are no workarounds available for this vulnerability. The only effective remediation is to upgrade to a fixed software release.

Evidence and validation checklist

  • Cisco Security Advisory ID cisco-sa-cuic-sql-inject-2qbfWSm5
  • CVE-2026-20327 assigned by Cisco PSIRT
  • Declaration of medium severity with CVSS base score of 6.5
  • No workarounds available as explicitly stated
  • Fixed software releases 12.6(2) ES08 and 15.0(1) SU2 identified
  • Exploitation requires valid user credentials

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source