ZeroHour

CVE-2026-76426

large

Authenticated SQL Injection in Cisco ISE and ISE-PIC REST API

CVSS 3.1
4.9 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-76426 is a SQL injection flaw (CWE-89) in the REST API of Cisco Identity Services Engine (ISE) and Cisco ISE-PIC (Passive Identity Connector), caused by insufficient validation of specific parameters that are concatenated into an SQL statement targeting the monitoring database. An attacker triggers it by sending a crafted REST API request containing SQL statements in one of the affected parameters, but must already hold valid administrative credentials. A successful exploit allows the attacker to read information from the monitoring database, with confidentiality impact only (CVSS 3.1 score of 4.9, medium). All organizations running ISE or ISE-PIC are potentially affected, though exploitation requires high-privilege access. No public proof-of-concept or confirmed exploitation of this specific flaw is known; however, related reporting describes a separate, actively exploited Cisco ISE zero-day authentication bypass (CVSS 10.0), so ISE administrators should patch urgently.

What to do: Upgrade ISE and ISE-PIC to the fixed releases identified in Cisco's advisory (version numbers not provided in the available data). Since exploitation requires valid administrative credentials, restrict and audit admin accounts, limit REST API access to trusted management networks, and review monitoring-database query and REST API logs for anomalous SQL content. Also monitor for the separately reported, actively exploited ISE authentication zero-day and check systems for signs of compromise.

Affected
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
Estimated exposure
large≈10,000–100,000 ISE/ISE-PIC deployments worldwide (estimated; no public install counts) — Cisco ISE is the company's flagship enterprise network access control/policy platform, typically deployed as appliance clusters in large enterprises, universities and government networks, so the order of magnitude is inferred from its…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.