CVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Description
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials.
In plain language
AI Act nowThis flaw lets someone with a Cisco ISE administrator account read monitoring data, so affected businesses should act urgently because public exploit code is available.
Authenticated remote SQL injection (CWE-89) in the Cisco ISE REST API allows an administrator-level attacker to inject crafted parameters into monitoring-database queries and read data.
What to do now
- Confirm whether you run cisco identity services engine software or cisco ise passive identity connector, and identify who has administrator access to their REST API.
- Remove unnecessary administrator accounts, require strong sign-in protection for remaining administrators, and restrict REST API access to trusted management networks.
- No fixed version has been published; check Cisco’s advisory and support channels for the official fixed release, then schedule the upgrade immediately when available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76426 and every CVE in our database. Create a free account — no credit card required.
Create Free Account