
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76451 is an SQL/HQL injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker with valid administrative credentials to execute arbitrary SQL or HQL queries against the underlying database. It was publicly disclosed on September 16, 2026, as part of a broader advisory (cisco-sa-ise-multisql-inject-JnHK54Rq) covering four related injection CVEs (CVE-2026-76448 through CVE-2026-76451). Affected versions span Cisco ISE 3.1.x through 3.5.x and ISE-PIC 3.1.0 through 3.5.0. The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium) (Cisco Advisory, GitHub Advisory).
The root cause is insufficient validation of user-supplied input to affected APIs before that input is used to construct database queries, classified as CWE-564 (SQL Injection: Hibernate) and CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). An attacker exploits this by sending a crafted HTTP request to a vulnerable API endpoint on the ISE or ISE-PIC device, injecting malicious SQL or HQL syntax that alters the intended query logic. Exploitation requires network access to the administrative interface and valid administrative credentials; no user interaction is needed beyond the attacker's own actions. The attack pattern aligns with CAPEC-109 (Object Relational Mapping Injection), reflecting the Hibernate ORM layer through which the injected queries are processed (Cisco Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL or HQL queries against the ISE or ISE-PIC underlying database, enabling unauthorized viewing or modification of sensitive data such as identity policies, user records, and network access configurations. The primary impact is to data integrity (rated High in CVSS), with no direct confidentiality or availability impact per the scoring; however, unauthorized data modification in an identity and access management platform could indirectly enable privilege escalation or policy bypass. Because ISE serves as a central network access control system, tampering with its database could have downstream effects on network segmentation and authentication enforcement across the enterprise (Cisco Advisory).
There is no evidence of public proof-of-concept exploit code or in-the-wild exploitation at the time of disclosure, according to both Cisco PSIRT and Feedly threat intelligence (Cisco Advisory). Cisco PSIRT notes that a public announcement of the vulnerability exists but is unaware of any malicious use. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. Exploitation requires valid administrative credentials, which significantly limits the attacker pool. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
' OR '1'='1 or more targeted HQL fragments to manipulate query logic or extract/modify specific database records.OR, UNION, SELECT, --) in query parameters; unexpected API calls from unfamiliar source IPs with administrative session tokens.Cisco has released fixed software versions to address this vulnerability; there are no workarounds available. Organizations should upgrade to the following minimum fixed releases: ISE 3.3 → Patch 12, ISE 3.4 → Patch 7, ISE 3.5 → Patch 4. ISE releases 3.1 and 3.2 are not receiving fixes and require migration to a supported fixed release. ISE-PIC 3.4 is the last supported release (end-of-sale). As interim defense-in-depth measures, restrict administrative access to ISE interfaces to only trusted personnel and trusted network segments, and monitor database and API activity for anomalous query patterns (Cisco Advisory).
Cisco credited Li Jiantao and Tevel Sho of STAR Labs SG Pte. Ltd. for discovering and reporting these vulnerabilities (Cisco Advisory). The advisory was published as part of Cisco's September 16, 2026 batch security advisory release. No significant independent researcher commentary, social media discussion, or notable media coverage beyond standard vulnerability tracking sites (CVEfeed, VulDB, AusCERT) has been observed at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."