Status: UPDATED | Advisory ID: CVE-2026-76425
| CVE | CVE-2026-76425 |
| CVSS Score / Version | 7.6 (High) / CVSS v3.1 |
| Updated | 2026-09-28 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none. |
| Affected products | Cisco Identity Services Engine and Cisco Identity Services Engine Software |
| Classified as | CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Cisco | Identity Services Engine | ||
| Cisco | Cisco Identity Services Engine Software |
| Subsystems | Industrial Networking & Connectivity |
| Sectors | Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems |
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database.
This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint. A successful exploit could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid administrative credentials. (NVD)
Monitor Cisco's web page for any future patch releases. See vendor advisory link below.