Junglewise Threat Intelligence

CVE-2026-76449: Cisco ISE SQL/HQL injection in APIs

CVE-2026-76449 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) are identity management and network access control products used by enterprises to manage authentication and authorization. A flaw in API input validation allows authenticated administrators to inject malicious SQL/HQL queries into the underlying database, enabling unauthorized access to or modification of sensitive identity and network data. This could expose user credentials, security policies, and network access logs.

Technical details

This vulnerability is a SQL/HQL injection flaw (CWE-89, CWE-564) in multiple APIs within Cisco ISE and ISE-PIC. The root cause is insufficient validation of user-supplied input before database query construction. An authenticated attacker with valid administrative credentials can send a crafted API request to an affected device to execute arbitrary SQL or HQL queries against the underlying database. A successful exploit allows viewing or modifying unauthorized data. The vulnerability requires network access and valid admin credentials. Cisco has released patches: ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4 and later address the issue. No workarounds are available.

Affected products

  • Cisco Identity Services Engine 3.1, 3.2, 3.3 (before patch 12), 3.4 (before patch 7), 3.5 (before patch 4)
  • Cisco ISE Passive Identity Connector 3.1, 3.2, 3.3 (before patch 12), 3.4 (before patch 7)

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Patches released: ISE 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

References

Related threats