Executive brief
Cisco Identity Services Engine (ISE) is an authentication and access control platform used to manage network identity and access policies. An authenticated attacker with administrative credentials can exploit SQL/HQL injection vulnerabilities in ISE APIs to read or modify sensitive data in the underlying database without authorization. The vulnerability requires valid admin credentials to exploit, limiting risk to insider threats and compromised admin accounts.
Technical details
The vulnerability is a SQL/HQL injection flaw (CWE-89) resulting from insufficient input validation in affected APIs before user-supplied data is incorporated into database queries. An authenticated attacker with administrative credentials can send crafted requests to exploit the vulnerability and execute arbitrary SQL or HQL queries against the database. A successful exploit allows unauthorized viewing or modification of data stored in the database. The attack requires network access, valid administrative credentials, and no user interaction. Cisco has released patched software versions (ISE 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4, and later); no workarounds exist.
Affected products
- Cisco Identity Services Engine 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7), 3.5 (before Patch 4)
- Cisco ISE Passive Identity Connector 3.1, 3.2, 3.3 (before Patch 12), 3.4 (before Patch 7)
Timeline
- 2026-09-16: disclosed: Cisco security advisory published
- 2026-09-16: patched: Fixed versions available: ISE 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4