Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76449
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-76449 is an SQL/HQL injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with administrative credentials to execute arbitrary database queries. It was publicly disclosed on September 16, 2026, as part of a broader advisory covering multiple related injection flaws (CVE-2026-76448, CVE-2026-76449, CVE-2026-76450, CVE-2026-76451). Affected versions span Cisco ISE and ISE-PIC releases 3.1.x through 3.5.x (including all patches up to the fixed releases). The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is insufficient validation of user-supplied input to affected APIs before that input is used to construct database queries, classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and CWE-564 (SQL Injection through Hibernate Query Language) (Cisco Advisory). An attacker exploits this by sending a crafted HTTP request to the vulnerable API endpoints, injecting malicious SQL or HQL syntax that is then interpreted and executed by the underlying database engine. Exploitation requires valid administrative credentials, limiting the attack surface to authenticated users with elevated privileges. No public proof-of-concept code has been identified at the time of disclosure (GitHub Advisory).

Impact

A successful exploit allows an authenticated attacker to execute arbitrary SQL or HQL queries against the ISE or ISE-PIC underlying database, enabling unauthorized viewing or modification of sensitive data such as identity policies, network access rules, and user/device records. The integrity impact is rated High, while confidentiality and availability are unaffected per the CVSS scoring, meaning the primary risk is unauthorized data tampering rather than data exfiltration or service disruption. Given ISE's role as a network access control and identity management platform, unauthorized modification of its database could have downstream effects on network segmentation and authentication decisions (Cisco Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at the time of disclosure (Cisco Advisory). Cisco PSIRT is aware that a public announcement exists for these vulnerabilities but has not observed malicious use. The EPSS score is 0.0, reflecting a very low current probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for valid administrative credentials, significantly reducing the likelihood of opportunistic attacks.

Mitigation and workarounds

Cisco has released fixed software versions to address this vulnerability; there are no workarounds available. Organizations should upgrade to the following fixed releases: Cisco ISE/ISE-PIC 3.3 → Patch 12, 3.4 → Patch 7, 3.5 → Patch 4. Releases 3.1 and 3.2 require migration to a supported fixed release. As interim measures, administrators should restrict administrative access to ISE and ISE-PIC to trusted users and networks, and monitor database query activity for anomalous SQL/HQL patterns (Cisco Advisory). Note that Cisco ISE-PIC has reached end-of-sale, with release 3.4 being the last supported version.

Community reactions

Cisco credited Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd. for responsibly reporting these vulnerabilities (Cisco Advisory). The advisory was picked up by standard vulnerability tracking services including AusCERT, VulDB, and CVEFeed shortly after publication, but no significant independent researcher commentary or social media discussion has been identified beyond routine aggregation.

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76460CRITICAL10
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
YesYesSep 16, 2026
CVE-2026-76451MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76450MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76449MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76448MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management