Cisco UIC Blind SQLi via Authenticated Local Attacker
CVE-2026-20327 Published on August 19, 2026
Cisco Unified Intelligence Center SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Vulnerability Analysis
CVE-2026-20327 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is a SQL Injection Vulnerability?
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
CVE-2026-20327 has been classified to as a SQL Injection vulnerability or weakness.
Products Associated with CVE-2026-20327
Want to know whenever a new CVE is published for Cisco Unified Intelligence Center? stack.watch will email you.
Affected Versions
Cisco Unified Intelligence Center:- Version 11.6(1) is affected.
- Version 10.5(1) is affected.
- Version 11.0(1) is affected.
- Version 11.5(1) is affected.
- Version 12.0(1) is affected.
- Version 12.5(1) is affected.
- Version 11.0(2) is affected.
- Version 12.6(1) is affected.
- Version 12.5(1)SU is affected.
- Version 12.6(1)_ET is affected.
- Version 12.6(1)_ES05_ET is affected.
- Version 11.0(3) is affected.
- Version 12.6(2) is affected.
- Version 12.6(2)_504_Issue_ET is affected.
- Version 12.6.1_ExcelIssue_ET is affected.
- Version 12.6(2)_Permalink_ET is affected.
- Version 12.6.2_CSCwk19536_ET is affected.
- Version 12.6.2_CSCwm96922_ET is affected.
- Version 12.6.2_Amq_OOS_ET is affected.
- Version 12.5(2)ET_CSCwi79933 is affected.
- Version 12.6(2)_ET is affected.
- Version 12.6.2_CSCwn48501_ET is affected.
- Version 15.0(1) is affected.
- Version 12.6.2_CSCwp61293_ET is affected.
- Version 15.0.1_CSCwn17585_ET is affected.
- Version 15.0(1)ES202508 is affected.
- Version 12.6.2_CSCwp92614_ET is affected.
- Version 15.0(1)ES202511 is affected.
- Version 12.6(2)ES6 is affected.
- Version 15.0(1)ES202602 is affected.
- Version 12.6(2)ES7 is affected.
- Version 15.0(1)SU1 is affected.
- Version 15.0.1_CSCwu05225_ET is affected.
- Version 15.0.1_CSCwu53931_ET is affected.
- Version 15.0.1_CSCwu75294_ET is affected.