{"id":"CVE-2026-76428","title":"A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database.\r\n\r\nThis vulnerability is due to certain parameters being concate…","summary":"A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database.\r\n\r\nThis vulnerability is due to certain parameters being concate…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"vendor":"Cisco","product":"Cisco Identity Services Engine Software","affected":["identity_services_engine_software 3.1.0","identity_services_engine_software 3.1.0 p1","identity_services_engine_software 3.1.0 p3","identity_services_engine_software 3.1.0 p2","identity_services_engine_software 3.2.0","identity_services_engine_software 3.1.0 p4","identity_services_engine_software 3.1.0 p5","identity_services_engine_software 3.2.0 p1","identity_services_engine_software 3.1.0 p6","identity_services_engine_software 3.2.0 p2","identity_services_engine_software 3.1.0 p7","identity_services_engine_software 3.3.0","identity_services_engine_software 3.2.0 p3","identity_services_engine_software 3.2.0 p4","identity_services_engine_software 3.1.0 p8","identity_services_engine_software 3.2.0 p5","identity_services_engine_software 3.2.0 p6","identity_services_engine_software 3.1.0 p9","identity_services_engine_software 3.3 Patch 2","identity_services_engine_software 3.3 Patch 1","identity_services_engine_software 3.3 Patch 3","identity_services_engine_software 3.4.0","identity_services_engine_software 3.2.0 p7","identity_services_engine_software 3.3 Patch 4","identity_services_engine_software 3.4 Patch 1","identity_services_engine_software 3.1.0 p10","identity_services_engine_software 3.3 Patch 5","identity_services_engine_software 3.3 Patch 6","identity_services_engine_software 3.4 Patch 2","identity_services_engine_software 3.3 Patch 7","identity_services_engine_software 3.4 Patch 3","identity_services_engine_software 3.5.0","identity_services_engine_software 3.4 Patch 4","identity_services_engine_software 3.3 Patch 8","identity_services_engine_software 3.2 Patch 8","identity_services_engine_software 3.5 Patch 1","identity_services_engine_software 3.3 Patch 9","identity_services_engine_software 3.2 Patch 9","identity_services_engine_software 3.4 Patch 5","identity_services_engine_software 3.5 Patch 3","identity_services_engine_software 3.5 Patch 2","identity_services_engine_software 3.3 Patch 10","identity_services_engine_software 3.3 Patch 11","identity_services_engine_software 3.4 Patch 6","identity_services_engine_software 3.2 Patch 10","identity_services_engine_software 3.1.0 p72","identity_services_engine_software 3.1.0 p11","identity_services_engine_software 3.3 Patch 12","ise_passive_identity_connector 3.2.0","ise_passive_identity_connector 3.1.0"],"published":"2026-09-16","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:17:12.100","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76428","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ","label":"psirt@cisco.com"},{"url":"https://software.cisco.com"}],"tags":["nvd","cve.org","csaf","vendor-advisory","cisco"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T14:36:24.819664Z"},"epss":0.00369,"epssPercentile":0.30641,"ingestedAt":"2026-09-16T16:37:52.201Z","slug":"CVE-2026-76428","body":"## Overview\n\nA vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database.\r\n\r\nThis vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the session database. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **cisco-sa-ise-multi-hrP9jQSQ** · Cisco · affected: Cisco ISE Passive Identity Connector (4 versions), Cisco Identity Services Engine Software (47 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ)","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}