CVE-2026-20327Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 108-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Cisco Unified Intelligence Center SQL Injection Vulnerability (CVE-2026-20327) https://www.systemtek.co.uk/2026/08/cisco-unified-intelligence-center-sql-injection-vulnerability-cve-2026-20327/ via @SystemTek_UK

    Post summary

    A new SQL injection vulnerability in Cisco Unified Intelligence Center, CVE-2026-20327, has been disclosed.

    0100066
    1.8K followersView on X

Explore more