SEPTEMBER 29, 2026
Live Feed
Back to database
Case File

CVE-2026-76446

MEDIUM · CVSS 4.9 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-09-29

CyberRota Analysis

AI-Generated

A vulnerability in the API of Cisco ISE and Cisco ISE-PIC allows authenticated remote attackers to exploit improper restrictions on XML external entity references, potentially enabling them to read sensitive files from the underlying operating system. The impact includes unauthorized access to file data, which could lead to further exploitation or data leakage. Organizations using affected Cisco products should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76446
Severity
MEDIUM
CVSS
4.9
EPSS
N/A
Cisco

Original NVD Description

A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read specific files on the affected system that the underlying process has permission to access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)