← All Advisories

CVE-2026-76425

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-76425

Key Details

CVECVE-2026-76425
CVSS Score / Version7.6 (High) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productsCisco Identity Services Engine and Cisco Identity Services Engine Software
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIdentity Services Engine
CiscoCisco Identity Services Engine Software
SubsystemsIndustrial Networking & Connectivity
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database.

This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint. A successful exploit could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid administrative credentials. (NVD)

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76425
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76425
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ