SQL Injection Vulnerability in Cisco Identity Services Engine and Connector
CVE-2026-76451

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76451?

A vulnerability in Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE-PIC) can lead to unauthorized SQL or HQL injection attacks. This issue arises from improper validation of user-supplied input for APIs, allowing attackers with valid administrative credentials to send specially crafted requests. Successful exploitation enables attackers to execute arbitrary database queries, risking unauthorized access to and modification of sensitive data.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.