Vulnerability in Cisco ISE's Offline Profiler Feed Service Exposes Sensitive Files
CVE-2026-76427

4.9MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-76427?

A vulnerability exists in the offline profiler feed service of Cisco ISE, allowing an authenticated remote attacker to read arbitrary files from the device's file system. This vulnerability arises from the handling of attacker-controlled XML feed metadata, specifically due to the XML parser's failure to disable external entity resolution. An attacker with valid administrative credentials can exploit this vulnerability by uploading a specially crafted offline feed package through the administrative interface. A successful exploitation could lead to unauthorized access to sensitive internal data and the ability to issue requests to internal systems from the affected Cisco ISE device.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.