CVE-2026-76425

HIGH

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient va...

CVSS 3.17.6
EPSS0.4%
Percentile32th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, high privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, no availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A high severity vulnerability (CVE-2026-76425) affects the target system. A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated ...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-76425?
A high severity vulnerability (CVE-2026-76425) affects the target system. A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated ...
What is the CVSS score for CVE-2026-76425?
CVE-2026-76425 has CVSS 7.6 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N. EPSS: 0.4%.
Is CVE-2026-76425 actively exploited?
No confirmed active exploitation of CVE-2026-76425 as of 2026-09-29.
How do I remediate CVE-2026-76425?
Apply vendor patches for CVE-2026-76425. Monitor the vendor advisories.
Vulnerability Details
CVE IDCVE-2026-76425
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Published2026-09-16
Last Modified2026-09-28
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint. A successful exploit could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid administrative credentials.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Cisco Identity Services Engine 3.3.0 3.4.0 3.5.0 ≥ 3.1.0, < 3.3.0
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 14 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →