CVE-2026-76426: Cisco ISE REST API SQL Injection Vulnerability
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to reach the REST API remotely and possess valid administrative credentials. Unauthenticated users are not described as able to exploit it.
What information could be exposed?
A successful SQL injection can allow the attacker to read information from the monitoring database. The provided information does not indicate that data can be modified or that service availability is affected.
Which products are identified as affected?
The affected products listed are Cisco ISE and Cisco ISE-PIC.