SQL and HQL Injection Vulnerability in Cisco Identity Services Engine
CVE-2026-76448

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76448?

A vulnerability exists in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that permits an authenticated, remote attacker to perform SQL and HQL injection attacks. This security flaw arises from inadequate validation of user input in the affected APIs, enabling crafted requests that can lead to executing unauthorized SQL or HQL queries against the database. Consequently, this may permit attackers to access or alter sensitive data, necessitating that they possess valid administrative credentials to execute such exploits.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.