XML External Entity injection in Cisco Identity Services Engine (ISE) - CVE-2026-76446

 

XML External Entity injection in Cisco Identity Services Engine (ISE) - CVE-2026-76446

Published: September 17, 2026


Vulnerability identifier: #VU150681
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76446
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read specific files on the underlying operating system.

The vulnerability exists due to improper restriction of XML external entity references in an API when processing crafted requests. A remote privileged user can send a crafted request to read specific files on the underlying operating system.

Accessible files are limited to those that the underlying process has permission to access.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2026-76446

Install security update from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4

External References

Related Security Bulletins