SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-76426
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read information from the monitoring database.
The vulnerability exists due to SQL injection in the REST API when processing parameters concatenated into an SQL statement. A remote privileged user can send a crafted request containing SQL statements in an affected parameter to read information from the monitoring database.