PT-2026-94027 · Cisco · Cisco Ise Passive Identity Connector+3

·

CVE-2026-76426

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco ISE (affected versions not specified) Cisco ISE-PIC (affected versions not specified)
Description An issue in the REST API allows an authenticated remote attacker with administrative credentials to perform SQL injection attacks against the monitoring database. This occurs because the system fails to sufficiently validate specific parameters before concatenating them into an SQL statement. An attacker can exploit this by sending a crafted request containing SQL statements in the affected parameters to read information from the monitoring database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76426

Affected Products

Cisco Ise Passive Identity Connector
Cisco Identity Services Engine
Identity Services Engine
Identity Services Engine Passive Identity Connector