CVE-2026-20327: Cisco Unified Intelligence Center
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Affected products
- Cisco Cisco Unified Intelligence Center: version 11.6(1) only; version 10.5(1) only; version 11.0(1) only; version 11.5(1) only; version 12.0(1) only; version 12.5(1) only; …
Published 2026-08-19. Last modified 2026-08-20.