SQL Injection Vulnerability in Cisco Identity Services Engine and Cisco ISE-PIC
CVE-2026-76426

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76426?

A vulnerability in the REST API of Cisco Identity Services Engine (ISE) and Cisco ISE-PIC allows an authenticated remote attacker to perform SQL injection attacks on the monitoring database. This issue arises from inadequate validation of specific parameters, which can be exploited when they are concatenated into an SQL statement. An attacker could send a specially crafted request containing malicious SQL code in one of the affected parameters. If successful, this could enable the attacker to access sensitive data from the monitoring database. It is important to note that valid administrative credentials are required for exploitation.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.