SQL injection in Cisco Identity Services Engine (ISE) - CVE-2026-76428
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read information from the session database.
The vulnerability exists due to SQL injection in the REST APIs when processing parameters concatenated directly into SQL clauses without parameterization. A remote privileged user can send a crafted request containing SQL statements in an affected parameter to read information from the session database.