SQL Injection Vulnerability in Cisco ISE APIs
CVE-2026-76425
What is CVE-2026-76425?
A vulnerability exists within the Cisco Identity Services Engine (ISE) APIs that permits an authenticated remote attacker to perform SQL injection attacks against the backend database. This security flaw arises from the inadequate validation of specific parameters that are directly concatenated into SQL queries. By transmitting a specially crafted request with SQL statements to exposed endpoints, an attacker can extract arbitrary data from the SQL database and potentially execute server-side request forgery (SSRF) attacks. Successful exploitation requires valid administrative credentials, emphasizing the need for secure credential management and thorough validation mechanisms.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3