XML External Entity injection in Cisco Identity Services Engine (ISE) - CVE-2026-76446
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read specific files on the underlying operating system.
The vulnerability exists due to improper restriction of XML external entity references in an API when processing crafted requests. A remote privileged user can send a crafted request to read specific files on the underlying operating system.
Accessible files are limited to those that the underlying process has permission to access.