SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-76425
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary content from the backend SQL database and conduct server-side request forgery attacks.
The vulnerability exists due to SQL injection in the Cisco ISE APIs when processing parameters concatenated directly into an SQL query. A remote privileged user can send a crafted request containing SQL statements to read arbitrary content from the backend SQL database and conduct server-side request forgery attacks.