Description
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device.

This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials.
Published: 2026-09-16
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Breach
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from insufficient validation of user‑supplied input to the APIs used by Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE‑PIC), enabling an authenticated remote attacker to inject SQL or HQL queries. Successful exploitation can lead to reading or modifying data that the attacker is not authorized to access, resulting in a confidentiality and integrity breach. The attack requires valid administrative credentials.

Affected Systems

Affected products are Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE‑PIC) as identified by the CNA. The advisory does not list specific versions, so all releases of these products prior to the published fix are considered vulnerable.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Because only authenticated attackers can exploit it, the threat is primarily internal or from compromised administrative credentials. Nonetheless, the potential to compromise sensitive data warrants prompt remediation.

Generated by OpenCVE AI on September 18, 2026 at 01:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco ISE security patch that addresses the SQL injection flaw, following the guidance in the Cisco advisory.
  • Limit administrative access to the ISE/ISE‑PIC components by restricting management access to trusted IP addresses or VPN endpoints.
  • Enforce strict role‑based access controls and monitor the system for anomalous database queries to detect possible exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco identity Services Engine
CPEs cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch10:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch11:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch7:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch8:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch9:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch6:*:*:*:*:*:*
Vendors & Products Cisco identity Services Engine

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials.
Title Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability
Weaknesses CWE-564
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Cisco Identity Services Engine Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-19T14:21:55.444Z

Reserved: 2026-08-19T12:02:03.636Z

Link: CVE-2026-76451

cve-icon Vulnrichment

Updated: 2026-09-19T14:18:29.943Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T21:17:21.300

Modified: 2026-09-28T13:03:39.380

Link: CVE-2026-76451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:07Z

Weaknesses