ZeroHour

CVE-2026-76425

large

Authenticated SQL Injection in Cisco ISE APIs Enables Database Read and SSRF

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

Cisco Identity Services Engine (ISE) contains a SQL injection flaw in its APIs caused by insufficient validation of parameters that are concatenated directly into backend database queries. An attacker who sends a specially crafted request containing SQL statements to an affected API endpoint can trigger the flaw, but valid administrative credentials are required to do so. A successful exploit allows the attacker to read arbitrary content from the SQL database and to conduct server-side request forgery (SSRF) attacks. All organizations running affected releases of Cisco ISE are potentially affected, though exploitation requires a privileged attacker account. As of now there is no evidence of in-the-wild exploitation and no public proof-of-concept is known, and the flaw is not listed in CISA's KEV catalog.

What to do: Check the Cisco PSIRT advisory for CVE-2026-76425 and upgrade ISE to a fixed release as soon as one is identified. Because exploitation requires valid administrative credentials, restrict access to the ISE admin and API interfaces to trusted management networks, enforce strong authentication and least privilege for admin accounts, and audit/rotate administrative credentials. Monitor API logs for unexpected queries and outbound requests that could indicate attempted SSRF.

Affected
Cisco Identity Services Engine (ISE) - APIs
Estimated exposure
large≈10,000-100,000 deployments worldwide (Cisco ISE is a leading enterprise NAC/policy platform, typically deployed on-premises per organization) — Cisco ISE is one of the most widely deployed enterprise network access control platforms with an install base on the order of tens of thousands of organizations, but admin/API interfaces are usually restricted to internal management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint. A successful exploit could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid administrative credentials.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.