Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76451
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2026-76451 is an SQL/HQL injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to execute arbitrary SQL or HQL queries against the underlying database. It was publicly disclosed on September 16, 2026, as part of a broader advisory (cisco-sa-ise-multisql-inject-JnHK54Rq) covering four related injection CVEs (CVE-2026-76448 through CVE-2026-76451). Affected versions span Cisco ISE 3.1.x through 3.5.x and ISE-PIC 3.1.0 through 3.5.0. The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is insufficient validation of user-supplied input to affected APIs before that input is used to construct database queries, classified as CWE-564 (SQL Injection: Hibernate) and CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). An attacker exploits this by sending a crafted HTTP request to a vulnerable API endpoint on the ISE or ISE-PIC device, injecting malicious SQL or HQL syntax that alters the intended query logic. Exploitation requires network access to the administrative interface and valid administrative credentials; no user interaction is needed beyond the attacker's own actions. The attack pattern aligns with CAPEC-109 (Object Relational Mapping Injection), reflecting the Hibernate ORM layer through which the injected queries are processed (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL or HQL queries against the ISE or ISE-PIC underlying database, enabling unauthorized viewing or modification of sensitive data such as identity policies, user records, and network access configurations. The primary impact is to data integrity (rated High in CVSS), with no direct confidentiality or availability impact per the scoring; however, unauthorized data modification in an identity and access management platform could indirectly enable privilege escalation or policy bypass. Because ISE serves as a central network access control system, tampering with its database could have downstream effects on network segmentation and authentication enforcement across the enterprise (Cisco Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or in-the-wild exploitation at the time of disclosure, according to both Cisco PSIRT and Feedly threat intelligence (Cisco Advisory). Cisco PSIRT notes that a public announcement of the vulnerability exists but is unaware of any malicious use. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. Exploitation requires valid administrative credentials, which significantly limits the attacker pool. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify Cisco ISE or ISE-PIC administrative interfaces exposed on the network (typically HTTPS on port 443 or 8443). Confirm the software version falls within the affected range (ISE 3.1.x–3.5.x or ISE-PIC 3.1.0–3.5.0) using banner information or version disclosure in the login page.
  2. Credential Acquisition: Obtain valid administrative credentials for the target ISE instance through phishing, credential stuffing, or insider access — exploitation requires high-privilege (administrative) authentication.
  3. Authenticate to the API: Log in to the ISE administrative interface or REST API using the obtained credentials to establish an authenticated session.
  4. Identify vulnerable API endpoints: Probe the ISE API endpoints that accept user-supplied query parameters and are used to build database queries. Based on the advisory, multiple APIs are affected (tracked under bug IDs CSCwu73800, CSCwu73804, CSCwu73813, CSCwu73822).
  5. Craft malicious SQL/HQL payload: Construct a request containing injected SQL or HQL syntax in the relevant parameter — for example, appending ' OR '1'='1 or more targeted HQL fragments to manipulate query logic or extract/modify specific database records.
  6. Send crafted request: Submit the crafted API request to the affected endpoint. The insufficient input validation allows the injected query fragment to be incorporated into the database query executed by the Hibernate ORM layer.
  7. Achieve objective: Review the API response for data returned from unauthorized database records, or confirm that unauthorized data modifications (e.g., policy changes, user record alterations) have taken effect (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or anomalous API requests to Cisco ISE administrative endpoints containing SQL/HQL metacharacters (e.g., single quotes, OR, UNION, SELECT, --) in query parameters; unexpected API calls from unfamiliar source IPs with administrative session tokens.
  • Logs: ISE application logs showing database query errors or unexpected query structures (e.g., Hibernate exceptions related to malformed HQL); administrative audit logs recording API calls with atypical parameter values or from unusual times/locations.
  • Database: Unexpected changes to ISE database records such as policy modifications, user account alterations, or new entries not corresponding to legitimate administrative actions; database query logs (if enabled) showing injected SQL/HQL syntax.
  • Authentication: Multiple failed login attempts followed by a successful administrative login from an unfamiliar IP, potentially indicating credential-based pre-exploitation activity.

Mitigation and workarounds

Cisco has released fixed software versions to address this vulnerability; there are no workarounds available. Organizations should upgrade to the following minimum fixed releases: ISE 3.3 → Patch 12, ISE 3.4 → Patch 7, ISE 3.5 → Patch 4. ISE releases 3.1 and 3.2 are not receiving fixes and require migration to a supported fixed release. ISE-PIC 3.4 is the last supported release (end-of-sale). As interim defense-in-depth measures, restrict administrative access to ISE interfaces to only trusted personnel and trusted network segments, and monitor database and API activity for anomalous query patterns (Cisco Advisory).

Community reactions

Cisco credited Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd. for discovering and reporting these vulnerabilities (Cisco Advisory). The advisory was published as part of Cisco's September 16, 2026 batch security advisory release. No significant independent researcher commentary, social media discussion, or notable media coverage beyond standard vulnerability tracking sites (CVEfeed, VulDB, AusCERT) has been observed at this time.

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76460CRITICAL10
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
YesYesSep 16, 2026
CVE-2026-76451MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76450MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76449MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026
CVE-2026-76448MEDIUM4.9
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management