SQL Injection Flaw in Cisco Identity Services Engine and Passive Identity Connector
CVE-2026-76449

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76449?

A security flaw exists in the Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) due to inadequate validation of user input for certain APIs. This vulnerability allows authenticated remote attackers to perform SQL or HQL injection attacks against the database. By sending specially crafted requests, an attacker with valid administrative credentials could execute unauthorized SQL or HQL queries, potentially leading to the unauthorized viewing or modification of sensitive data.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.