SQL Injection Vulnerability in Cisco ISE and Cisco ISE-PIC
CVE-2026-76428
What is CVE-2026-76428?
A vulnerability exists in the REST APIs of Cisco ISE and Cisco ISE-PIC, enabling an authenticated remote attacker to execute SQL injection attacks on the session database. This critical issue arises from the improper handling of certain parameters, which are directly concatenated into SQL statements without adequate parameterization. By issuing a specially crafted request with SQL commands embedded in the parameters, an attacker could potentially gain unauthorized access to sensitive data stored in the session database. To successfully exploit this vulnerability, the attacker must possess valid administrative credentials, emphasizing the importance of securing access controls.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3