Junglewise Threat Intelligence

CVE-2026-76446: Cisco ISE external entity injection in API

CVE-2026-76446 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) are network authentication and access control systems used by enterprises to manage user and device access to networks. A vulnerability in an API allows authenticated remote attackers to read arbitrary files on the affected system by exploiting improper handling of XML external entity references. This could expose sensitive configuration data, credentials, or other confidential information stored on the system.

Technical details

The vulnerability is a classic XML External Entity (XXE) injection flaw in an API of Cisco ISE and ISE-PIC, classified under CWE-611. The root cause is improper restriction of XML external entity references in the affected API. An authenticated, remote attacker can craft and send a malicious XML request to trigger arbitrary file read on the underlying operating system, with access limited to files readable by the ISE process. Attack precondition is valid authentication; no user interaction required. A successful exploit allows information disclosure of sensitive system files. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Identity Services Engine <UNKNOWN>
  • Cisco ISE Passive Identity Connector <UNKNOWN>

Timeline

  • 2026-09-16: disclosed: Vulnerability disclosed; software updates available

References

Related threats