PT-2026-94016 · Cisco · Cisco Ise Passive Identity Connector+3

·

CVE-2026-76451

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified) Cisco ISE Passive Identity Connector (ISE-PIC) (affected versions not specified)
Description An authenticated remote attacker with valid administrative credentials can perform SQL or HQL (Hibernate Query Language) injection attacks. This issue stems from insufficient validation of user-supplied input sent to affected APIs before the input is used to construct database queries. By sending a crafted request, an attacker can execute arbitrary queries against the underlying database to view or modify unauthorized data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76451

Affected Products

Cisco Ise Passive Identity Connector
Cisco Identity Services Engine
Identity Services Engine
Identity Services Engine Passive Identity Connector