CVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Public exploit available. Not confirmed exploited in the wild yet. No fix published yet.
What to do
No fixed build or workaround is published yet. Limit exposure and watch for a patch.
Steps
Written by AI from the record- Check whether you run Cisco Identity Services Engine software and whether administrators can upload offline profiler feed packages.
- Restrict administrator accounts to essential staff, remove unused accounts, and require strong sign-in protection for remaining administrators.
- No fixed version has been published in the available findings; ask Cisco or your support partner for the applicable fixed release before upgrading.
- Until a fix is available, disable or tightly control offline profiler feed uploads and review administrator activity for unexpected uploads.
What it is
From the CVE record
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
In plain language
Written by AI from the recordThis affects Cisco Identity Services Engine software; an attacker with an administrator account may be able to read sensitive files, and no vendor fix information is available.
Authenticated remote XML external entity injection in Cisco ISE’s offline profiler feed service lets an administrator-uploaded crafted feed read arbitrary local files and make requests to internal systems.
If you're affected
- Sensitive file exposure
- Internal system probing
- Identity service risk
- Administrative account abuse
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
0 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
0.5% chance of exploitation activity in the next 30 days, which ranks it in the 37th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
5 events over 2 days, from the signal feeds we watch.
- Record updated
- Publishedweakness classified, att&ck mapped, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Scored 4.9 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required HighRequires admin or elevated privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity NoneNo integrity impact
- Availability NoneNo availability impact
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cisco, not every advisory. This one: public exploit.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI