Cisco ISE Offline Profiler XML External Entity Read Arbitrary File
CVE-2026-76427 Published on September 16, 2026
Cisco ISE XML External Entity Injection Vulnerability
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device.
This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
Vulnerability Analysis
CVE-2026-76427 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2026-76427 has been classified to as a XXE vulnerability or weakness.
Products Associated with CVE-2026-76427
Want to know whenever a new CVE is published for Cisco Identity Services Engine Software? stack.watch will email you.
Affected Versions
Cisco Identity Services Engine Software:- Version 3.1.0 is affected.
- Version 3.1.0 p1 is affected.
- Version 3.1.0 p3 is affected.
- Version 3.1.0 p2 is affected.
- Version 3.2.0 is affected.
- Version 3.1.0 p4 is affected.
- Version 3.1.0 p5 is affected.
- Version 3.2.0 p1 is affected.
- Version 3.1.0 p6 is affected.
- Version 3.2.0 p2 is affected.
- Version 3.1.0 p7 is affected.
- Version 3.3.0 is affected.
- Version 3.2.0 p3 is affected.
- Version 3.2.0 p4 is affected.
- Version 3.1.0 p8 is affected.
- Version 3.2.0 p5 is affected.
- Version 3.2.0 p6 is affected.
- Version 3.1.0 p9 is affected.
- Version 3.3 Patch 2 is affected.
- Version 3.3 Patch 1 is affected.
- Version 3.3 Patch 3 is affected.
- Version 3.4.0 is affected.
- Version 3.2.0 p7 is affected.
- Version 3.3 Patch 4 is affected.
- Version 3.4 Patch 1 is affected.
- Version 3.1.0 p10 is affected.
- Version 3.3 Patch 5 is affected.
- Version 3.3 Patch 6 is affected.
- Version 3.4 Patch 2 is affected.
- Version 3.3 Patch 7 is affected.
- Version 3.4 Patch 3 is affected.
- Version 3.5.0 is affected.
- Version 3.4 Patch 4 is affected.
- Version 3.3 Patch 8 is affected.
- Version 3.2 Patch 8 is affected.
- Version 3.5 Patch 1 is affected.
- Version 3.3 Patch 9 is affected.
- Version 3.2 Patch 9 is affected.
- Version 3.4 Patch 5 is affected.
- Version 3.5 Patch 3 is affected.
- Version 3.5 Patch 2 is affected.
- Version 3.3 Patch 10 is affected.
- Version 3.3 Patch 11 is affected.
- Version 3.4 Patch 6 is affected.
- Version 3.2 Patch 10 is affected.
- Version 3.1.0 p72 is affected.
- Version 3.1.0 p11 is affected.
- Version 3.3 Patch 12 is affected.
- Version 3.2.0 is affected.
- Version 3.1.0 is affected.
- Version 3.3.0 is affected.
- Version 3.4.0 is affected.
- Version 3.5.0 is affected.