Junglewise Threat Intelligence

CVE-2026-76448: Cisco Identity Services Engine SQL and HQL injection

CVE-2026-76448 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) are identity and access management systems that control user authentication and authorization across networks. An authenticated administrator with valid credentials can inject malicious SQL or HQL queries through vulnerable APIs, potentially allowing them to view, modify, or delete sensitive user identity data stored in the underlying database. An attacker with compromised administrative credentials could escalate their access or manipulate identity records to bypass security controls.

Technical details

Multiple SQL and HQL injection vulnerabilities exist in Cisco ISE and ISE-PIC due to insufficient input validation on affected APIs before the input is used to construct database queries (CWE-89, CWE-564). An authenticated remote attacker with valid administrative credentials can exploit these vulnerabilities by sending a crafted request to the affected device. A successful exploit allows execution of arbitrary SQL or HQL queries against the underlying database, potentially enabling unauthorized data access, modification, or deletion. Cisco has released software patches: ISE 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4 contain the fixes. ISE 3.1 and 3.2 reached end-of-support and require migration to a fixed release.

Affected products

  • Cisco Identity Services Engine 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7), 3.5 (before Patch 4)
  • Cisco ISE Passive Identity Connector 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7)

Timeline

  • 2026-09-16: disclosed: Cisco security advisory published

References

Related threats