XML External Entity injection in Cisco Identity Services Engine (ISE) - CVE-2026-76427
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary files and issue requests to internal systems.
The vulnerability exists due to XML external entity injection in the offline profiler feed service when parsing attacker-controlled feed metadata with an XML parser that permits external entity resolution. A remote privileged user can upload a crafted offline feed package through the administrative interface to read arbitrary files and issue requests to internal systems.