Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
4.9
CVE-2026-76426
Cisco · Cisco Identity Services Engine Software

Cisco ISE REST API SQL Injection Vulnerability

Description

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p72, 3.1.0 p11, 3.3 Patch 12, 3.2.0, 3.1.0, 3.3.0, 3.4.0, 3.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco ise passive identity connectormitre_affected90%
ciscisco secure firewall management centercert_advisory90%
cisidentity services engine (ise)cert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ

Related News (4 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco ISE und ISE-PIC: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco Secure Firewall Management Center: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-76426 | Cisco Identity Services Engine Software REST API sql injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.14.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-89
PublishedSep 16, 2026
Last enriched11d ago
Trending Score11
Source articles4
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 13
MEDIUMCVE-2026-20121
CIsco FTD Bypass Access List
Trending: 13
MEDIUMCVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Trending: 11
MEDIUMCVE-2026-76431
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
Trending: 10
HIGHCVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026