SB20260917237 - Multiple vulnerabilities in Cisco Identity Services Engine
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2026-76423)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H]
The vulnerability allows a remote attacker to gain administrative access and read and modify configuration and identity data.
The vulnerability exists due to insufficient authorization checks in the REST API web service when handling crafted HTTP requests to the exposed REST API port. A remote attacker can send a crafted HTTP request to gain administrative access and read and modify configuration and identity data.
2) Relative Path Traversal (CVE-ID: CVE-2026-76424)
CWE-ID: CWE-23 - Relative Path Traversal
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to insufficient validation in file operations when uploading a file with a crafted path. A remote privileged user can upload a file with a crafted path to execute arbitrary commands as root.
3) SQL injection (CVE-ID: CVE-2026-76425)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read arbitrary content from the backend SQL database and conduct server-side request forgery attacks.
The vulnerability exists due to SQL injection in the Cisco ISE APIs when processing parameters concatenated directly into an SQL query. A remote privileged user can send a crafted request containing SQL statements to read arbitrary content from the backend SQL database and conduct server-side request forgery attacks.
4) SQL injection (CVE-ID: CVE-2026-76426)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read information from the monitoring database.
The vulnerability exists due to SQL injection in the REST API when processing parameters concatenated into an SQL statement. A remote privileged user can send a crafted request containing SQL statements in an affected parameter to read information from the monitoring database.
5) XML External Entity injection (CVE-ID: CVE-2026-76427)
CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read arbitrary files and issue requests to internal systems.
The vulnerability exists due to XML external entity injection in the offline profiler feed service when parsing attacker-controlled feed metadata with an XML parser that permits external entity resolution. A remote privileged user can upload a crafted offline feed package through the administrative interface to read arbitrary files and issue requests to internal systems.
6) SQL injection (CVE-ID: CVE-2026-76428)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read information from the session database.
The vulnerability exists due to SQL injection in the REST APIs when processing parameters concatenated directly into SQL clauses without parameterization. A remote privileged user can send a crafted request containing SQL statements in an affected parameter to read information from the session database.
Remediation
Install update from vendor's website.