
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76448 is an SQL/HQL injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with administrative credentials to execute arbitrary database queries. It was publicly disclosed on September 16, 2026, as part of a broader advisory covering multiple related injection flaws (CVE-2026-76448 through CVE-2026-76451). Affected versions span Cisco ISE and ISE-PIC releases 3.1.x through 3.5.x across numerous patch levels. The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).
The root cause is insufficient validation of user-supplied input to affected APIs before that input is used to construct database queries, classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and CWE-564 (SQL Injection through Hibernate Query Language). An attacker exploits this by sending a crafted HTTP request to a vulnerable API endpoint on the ISE or ISE-PIC device, injecting malicious SQL or HQL syntax that alters the intended query logic. Exploitation requires valid administrative credentials, meaning the attack vector is network-accessible but gated behind high-privilege authentication. No public proof-of-concept code has been identified at the time of disclosure (Cisco Advisory).
A successful exploit allows an authenticated attacker to execute arbitrary SQL or HQL queries against the underlying database of the affected Cisco ISE or ISE-PIC device. The primary impact is a high integrity risk — an attacker can view or modify data they are not authorized to access, potentially including authentication policies, identity records, and network access control configurations. Confidentiality and availability are not directly impacted per the CVSS scoring, but unauthorized modification of ISE policy data could have significant downstream effects on network access control decisions (Cisco Advisory, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at the time of disclosure. The EPSS score is 0.0, reflecting a currently low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Cisco PSIRT noted awareness of a public announcement for the vulnerability group but confirmed no known malicious use. Exploitation requires valid administrative credentials, which significantly limits the attacker pool (Cisco Advisory).
' OR '1'='1 or HQL-specific syntax to manipulate query logic).OR, UNION, SELECT keywords in parameter values).Cisco has released fixed software versions to address this vulnerability. Organizations should upgrade to the following minimum releases: Cisco ISE/ISE-PIC 3.3 → Patch 12; 3.4 → Patch 7; 3.5 → Patch 4. Releases 3.1 and 3.2 require migration to a fixed release, as no patch is available for those branches. There are no workarounds available. As interim measures, Cisco recommends restricting administrative access to ISE and ISE-PIC to only trusted personnel, implementing network segmentation to limit access, and monitoring database query logs for suspicious activity (Cisco Advisory).
Cisco credited Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd. for discovering and reporting these vulnerabilities. The advisory was published as part of Cisco's September 16, 2026 batch of security advisories and is also referenced in the Cisco Identity Services Engine Security Hardening Release for September 2026. No significant independent researcher commentary or broad social media discussion has been identified beyond standard vulnerability aggregator coverage (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."