Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76448
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-76448 is an SQL/HQL injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with administrative credentials to execute arbitrary database queries. It was publicly disclosed on September 16, 2026, as part of a broader advisory covering multiple related injection flaws (CVE-2026-76448 through CVE-2026-76451). Affected versions span Cisco ISE and ISE-PIC releases 3.1.x through 3.5.x across numerous patch levels. The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is insufficient validation of user-supplied input to affected APIs before that input is used to construct database queries, classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and CWE-564 (SQL Injection through Hibernate Query Language). An attacker exploits this by sending a crafted HTTP request to a vulnerable API endpoint on the ISE or ISE-PIC device, injecting malicious SQL or HQL syntax that alters the intended query logic. Exploitation requires valid administrative credentials, meaning the attack vector is network-accessible but gated behind high-privilege authentication. No public proof-of-concept code has been identified at the time of disclosure (Cisco Advisory).

Impact

A successful exploit allows an authenticated attacker to execute arbitrary SQL or HQL queries against the underlying database of the affected Cisco ISE or ISE-PIC device. The primary impact is a high integrity risk — an attacker can view or modify data they are not authorized to access, potentially including authentication policies, identity records, and network access control configurations. Confidentiality and availability are not directly impacted per the CVSS scoring, but unauthorized modification of ISE policy data could have significant downstream effects on network access control decisions (Cisco Advisory, GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at the time of disclosure. The EPSS score is 0.0, reflecting a currently low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Cisco PSIRT noted awareness of a public announcement for the vulnerability group but confirmed no known malicious use. Exploitation requires valid administrative credentials, which significantly limits the attacker pool (Cisco Advisory).

Exploitation steps

  1. Obtain Administrative Credentials: Acquire valid administrative credentials for the target Cisco ISE or ISE-PIC instance through phishing, credential stuffing, or insider access.
  2. Identify Target API Endpoint: Authenticate to the ISE administrative interface and identify API endpoints that accept user-supplied parameters used in database queries (e.g., search or filter parameters in the ISE REST API or admin UI).
  3. Craft Malicious Payload: Construct a crafted HTTP request containing SQL or HQL injection syntax in the vulnerable parameter (e.g., appending ' OR '1'='1 or HQL-specific syntax to manipulate query logic).
  4. Send Crafted Request: Submit the crafted request to the affected API endpoint on the ISE device over the network.
  5. Execute Arbitrary Queries: If successful, the injected SQL or HQL is interpreted by the underlying database engine, allowing the attacker to retrieve or modify unauthorized data such as identity records, policy configurations, or session data (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or malformed API requests to Cisco ISE administrative or REST API endpoints containing SQL/HQL metacharacters (e.g., single quotes, OR, UNION, SELECT keywords in parameter values).
  • Logs: ISE application logs showing database query errors or unexpected query structures; authentication logs showing administrative logins from unusual source IPs or at unusual times.
  • Database: Unexpected data modifications in ISE policy or identity tables; query logs (if enabled) showing anomalous SELECT or UPDATE statements not consistent with normal administrative activity.

Mitigation and workarounds

Cisco has released fixed software versions to address this vulnerability. Organizations should upgrade to the following minimum releases: Cisco ISE/ISE-PIC 3.3 → Patch 12; 3.4 → Patch 7; 3.5 → Patch 4. Releases 3.1 and 3.2 require migration to a fixed release, as no patch is available for those branches. There are no workarounds available. As interim measures, Cisco recommends restricting administrative access to ISE and ISE-PIC to only trusted personnel, implementing network segmentation to limit access, and monitoring database query logs for suspicious activity (Cisco Advisory).

Community reactions

Cisco credited Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd. for discovering and reporting these vulnerabilities. The advisory was published as part of Cisco's September 16, 2026 batch of security advisories and is also referenced in the Cisco Identity Services Engine Security Hardening Release for September 2026. No significant independent researcher commentary or broad social media discussion has been identified beyond standard vulnerability aggregator coverage (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76460CRITICAL10
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
YesYesSep 16, 2026
CVE-2026-76451MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76450MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76449MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76448MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management