Executive Summary
CVE-2026-76451 is a SQL and HQL injection flaw in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) caused by insufficient validation of user-supplied input to affected APIs before it is used to build database queries. An authenticated remote attacker sending a crafted request can execute arbitrary queries against the underlying database, and in OT environments this database backs the authentication and authorization decisions that gate access to industrial network segments.
Technical Exposure Breakdown
The vulnerable component is the API layer that constructs database queries from user-supplied parameters. The failure mode is standard: parameters are concatenated or otherwise interpolated into SQL or Hibernate Query Language statements without adequate sanitization or parameterized binding. The distinction between SQL and HQL matters here. HQL operates against the object relational mapping layer, which means an attacker may be able to traverse entity relationships and reach data that is not directly exposed by any single table view.
The precondition is authentication. Per the grounding data this carries a CVSS score of 4.9, which reflects the authenticated prerequisite and a scope limited to the database rather than full host compromise. That score understates the operational consequence in an identity platform. ISE is not a data store you can treat as low value. It holds policy definitions, endpoint profiles, credential material references, and the mapping between identities and network authorization. Read or write access to that store is access to the control logic of your network segmentation.
The attacker model assumes a valid account. In many deployments the population of accounts with API reach is larger than operators assume. Read-only operators, integration service accounts, monitoring tools, and third-party connectors frequently hold credentials that satisfy the authentication precondition. An attacker who has phished a low-privilege operator or captured a service account token now has a path from that limited foothold to the identity database.
OT Impact and Compliance Risk
ISE commonly sits at the boundary between IT and OT, enforcing 802.1X, MAB, and downloadable ACLs that decide whether a device lands in a corporate VLAN or a process control segment. If an attacker can manipulate the backing database, the integrity of every downstream authorization decision is in question. A modified policy or authorization profile can silently place an untrusted device inside a protected zone. This is a segmentation bypass expressed through the identity plane rather than through a firewall rule.
For NERC CIP registered entities, CIP-005 electronic security perimeter and CIP-007 system security management assumptions rest on the integrity of access control enforcement. A compromised ISE database undermines the evidence that access is being controlled as documented. Under IEC 62443, this attacks the zone and conduit model at its enforcement point rather than at a single asset. For pipeline operators under TSA SD-02C, the requirement to segment OT from IT and to enforce access control depends on the identity infrastructure being trustworthy. Water utilities under AWIA 2018 obligations face the same logic where ISE mediates plant network access.
Compensating Controls
Do not point active scanners at ISE nodes reachable from OT segments to hunt for this. Aggressive API probing against an authentication platform can degrade authentication services, and a stalled RADIUS response can cascade into failed device onboarding on the plant floor.
- Reduce the authenticated attack surface. Audit every account and service token with API access and remove or scope down anything that does not require it. This directly attacks the precondition.
- Restrict API endpoint reachability by ACL to a hardened management enclave. The ISE administrative and API interfaces should not be reachable from OT operator subnets or from general IT.
- Deploy a virtual patch at the network layer. A Suricata rule concept: inspect HTTP request bodies and query parameters bound for ISE API paths for SQL and HQL metacharacter sequences and keyword patterns such as UNION, single quote followed by boolean tautology, and HQL entity traversal syntax, then alert and drop on management-facing sensors.
- Enable and forward ISE database and API audit logging to a SIEM outside the ISE trust boundary, so tampering of the local store does not erase the evidence trail.
- Where patch status is confirmed by the vendor, stage the update in a maintenance window with rollback, since ISE upgrades touch live authentication paths.
BreachSpider Intel
BreachSpider tracks exploitation signals and patch movement for CVE-2026-76451 across ICS and OT-adjacent identity infrastructure so operators can prioritize before this reaches a known exploited vulnerability catalog listing.