Junglewise Threat Intelligence

CVE-2026-76427: Cisco ISE XML external entity injection in offline profiler feed service

CVE-2026-76427 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is an authentication and access control platform used to manage corporate network access. A vulnerability in its offline profiler feed service allows authenticated administrators with malicious intent to read arbitrary files from the system and make requests to internal services. An attacker with administrative credentials could exploit this to expose sensitive configuration data or compromise internal network resources.

Technical details

This vulnerability is an XML External Entity (XXE) injection flaw in the offline profiler feed service. The root cause is insufficient configuration of the XML parser used to parse attacker-controlled feed metadata—specifically, external entity resolution is not disabled. An authenticated remote attacker with valid administrative credentials can upload a crafted offline feed package through the administrative interface. A successful exploit allows the attacker to read arbitrary files from the affected device's file system and issue requests to internal systems. Patches are available from Cisco.

Affected products

  • Cisco Identity Services Engine multiple versions affected

Timeline

  • 2026-09-16: disclosed

References

Related threats