PT-2026-94004 · Cisco · Ise

CVE-2026-76425

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco ISE (affected versions not specified)
Description Insufficient validation of certain parameters concatenated into SQL queries in the APIs allows an authenticated remote attacker with administrative credentials to perform SQL injection attacks against the backend database. By sending crafted requests to an affected endpoint, an attacker can read arbitrary content from the database and execute server-side request forgery (SSRF) attacks, where the server is coerced into making unauthorized requests to other internal or external systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76425

Affected Products

Ise