SQL Injection Flaw in Cisco Identity Services Engine and Passive Identity Connector
CVE-2026-76449
4.9MEDIUM
What is CVE-2026-76449?
A security flaw exists in the Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) due to inadequate validation of user input for certain APIs. This vulnerability allows authenticated remote attackers to perform SQL or HQL injection attacks against the database. By sending specially crafted requests, an attacker with valid administrative credentials could execute unauthorized SQL or HQL queries, potentially leading to the unauthorized viewing or modification of sensitive data.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3