Description
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device.

This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
Published: 2026-09-16
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Check for Updates
AI Analysis

Impact

The vulnerability arises from the offline profiler feed service’s XML parser not disabling external entity resolution. An attacker who has valid administrative credentials can upload a crafted offline feed package through the administrative interface. If the upload succeeds, the service parses the feed metadata and resolves external entity references, enabling the attacker to read arbitrary files from the device’s file system and issue requests to internal systems. This gives the attacker the ability to exfiltrate sensitive files and potentially use the device as a pivot point for further internal network activity.

Affected Systems

The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. Specific release versions are not enumerated in the advisory, so any installation of the documented products that has not been updated with the security release may be vulnerable.

Risk and Exploitability

The CVSS score of 4.9 indicates a moderate severity, while an EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog, suggesting that no widespread public exploits are known. Because the attack requires authenticated administrative access, the risk is limited to environments where such credentials are available. Nonetheless, the potential for read‑of‑arbitrary files and internal request execution makes the impact significant for protecting confidential data.

Generated by OpenCVE AI on September 18, 2026 at 01:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict the feed upload interface so that only trusted administrative hosts can access it, and block all other network traffic to that interface.
  • Configure the XML parser used by the service to reject external entity references or validate feed files against a known whitelist before processing, thereby preventing malicious entity resolution.
  • Check Cisco for any available security updates or advisories related to this vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco identity Services Engine
CPEs cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch6:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch3:*:*:*:*:*:*
Vendors & Products Cisco identity Services Engine

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Passive Identity Connector
Cisco identity Services Engine Software

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
Title Cisco ISE XML External Entity Injection Vulnerability
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Identity Services Engine Identity Services Engine Passive Identity Connector Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T14:45:22.322Z

Reserved: 2026-08-19T12:02:03.634Z

Link: CVE-2026-76427

cve-icon Vulnrichment

Updated: 2026-09-18T14:36:34.412Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T21:17:14.393

Modified: 2026-09-28T13:01:50.520

Link: CVE-2026-76427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:38:10Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference