ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection RCE Vulnerability

Executive Summary

A command injection flaw in Cisco Identity Services Engine’s createDBLink function allows authenticated attackers to execute arbitrary code remotely. The vulnerability, identified as CVE-2026-20176, carries a CVSS score of 7.2 and was disclosed by the Zero Day Initiative.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-18T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.

"What lies behind us and what lies before us are tiny matters compared to what lies within us."

— Walt Emerson
Source: Zero Day Initiative