Vulnerability in Cisco ISE's Offline Profiler Feed Service Exposes Sensitive Files
CVE-2026-76427
What is CVE-2026-76427?
A vulnerability exists in the offline profiler feed service of Cisco ISE, allowing an authenticated remote attacker to read arbitrary files from the device's file system. This vulnerability arises from the handling of attacker-controlled XML feed metadata, specifically due to the XML parser's failure to disable external entity resolution. An attacker with valid administrative credentials can exploit this vulnerability by uploading a specially crafted offline feed package through the administrative interface. A successful exploitation could lead to unauthorized access to sensitive internal data and the ability to issue requests to internal systems from the affected Cisco ISE device.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3