Executive Summary

CVE-2026-76449 is an authenticated SQL and HQL injection flaw in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) caused by insufficient validation of user-supplied input before it is used to construct database queries. Because ISE frequently governs authentication and segmentation policy at the boundary between enterprise IT and plant OT networks, corruption or exfiltration of its identity store can quietly dissolve the access controls that keep untrusted hosts off industrial VLANs.

Technical Exposure Breakdown

The vulnerable component is a set of ISE and ISE-PIC APIs that accept user-supplied parameters and pass them into backend database queries without sufficient validation. An authenticated, remote attacker sends a crafted request to one of these APIs and injects arbitrary SQL or HQL. HQL is the Hibernate query language, which sits above the relational layer, so injection here can manipulate the object model as well as the underlying tables.

The precondition is authentication. This is not an unauthenticated pre-auth break. That places the risk in the hands of anyone holding valid credentials to the ISE administrative or API surface, including compromised operator accounts, over-privileged integration service accounts, and stolen API tokens. In many deployments the ISE API is reachable from more of the network than operators assume, and it is often exposed to automation and orchestration systems that hold standing credentials.

The grounding data lists a CVSS score of 4.9 and does not confirm patch availability. Treat the moderate score with caution. CVSS reflects the mechanism, not the blast radius in your architecture. In an environment where ISE is the single arbiter of who reaches the control network, the practical impact of database manipulation can exceed what the base score suggests.

OT Impact and Compliance Risk

ISE is commonly deployed as the network access control and policy enforcement engine feeding TrustSec tags, dot1x authentication, and dynamic VLAN assignment. If an attacker can read or alter the identity and policy store, several failure modes follow. Read access can expose endpoint inventories, MAC address bindings, and policy structure, which is high-value reconnaissance for anyone mapping a plant network. Write access, depending on what the injection reaches, could degrade the integrity of authorization decisions. The physical consequence is not the database corruption itself but the loss of assurance that only authorized devices and users touch PLCs, RTUs, HMIs, and engineering workstations.

Compliance exposure is direct. Under NERC CIP, ISE often supports electronic access controls and access management evidence tied to CIP-005 and CIP-007. Compromise of the identity store undermines the integrity of that evidence and the controls themselves. For IEC 62443, this maps to zone and conduit enforcement and to identification and authentication requirements in the SR families. Pipeline operators under TSA SD-02C rely on network segmentation and access control that ISE frequently implements, so a weakened NAC layer is a segmentation finding. Water and wastewater utilities under AWIA 2018 that use ISE for remote access governance face the same trust erosion.

Compensating Controls

Do not treat active scanning of ISE-adjacent OT segments as a discovery method. Aggressive probing can disrupt authentication flows and, downstream, brick or knock offline the industrial components that depend on those flows for network admission. Inventory ISE reachability through configuration review, not scanning.

Confirm fixed releases directly with the vendor advisory before scheduling any change, since patch status is not established in the available data and ISE upgrades require careful sequencing to avoid interrupting authentication in production.

BreachSpider Intel

BreachSpider tracks CVE-2026-76449 and other identity and access control exposures at the IT/OT boundary so you can prioritize remediation against your specific ISE deployment.