Junglewise Threat Intelligence

CVE-2026-76450: Cisco Identity Services Engine SQL and HQL injection

CVE-2026-76450 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are identity management platforms used to control network access and enforce security policies. A vulnerability allows authenticated administrators to inject malicious database queries, potentially exposing or modifying sensitive network access and user identity data. Exploitation requires valid admin credentials but could compromise the integrity and confidentiality of all data managed by the system.

Technical details

The vulnerability is a SQL and HQL injection flaw (CWE-89) arising from insufficient input validation in affected APIs before user-supplied input is incorporated into database queries. An authenticated remote attacker with valid administrative credentials can send a crafted request to exploit this vulnerability. Successful exploitation allows execution of arbitrary SQL or HQL queries against the underlying database, enabling unauthorized data access and modification. Cisco has released patches: ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4 address the issue; releases 3.1 and 3.2 require migration to a fixed release.

Affected products

  • Cisco Identity Services Engine 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7), 3.5 (before Patch 4)
  • Cisco ISE Passive Identity Connector 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7)

Timeline

  • 2026-09-16: disclosed: Cisco security advisory published

References

Related threats