Cisco ISE Vulnerability Enables Access to Sensitive Data
Cisco has identified a new XML External Entity (XXE) vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability could enable authenticated attackers with administrative access to retrieve…
Cisco has identified a new XML External Entity (XXE) vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability could enable authenticated attackers with administrative access to retrieve sensitive data from the underlying operating system.
The vulnerability is tracked as CVE-2026-20029 and has a CVSS rating of 4.9, indicating medium severity. Despite this rating, the vulnerability poses significant risks in environments where ISE functions as a central policy and identity control plane.
The issue arises from improper XML parsing within the licensing features accessible via the web-based management interface. An attacker with valid administrative credentials can exploit this by uploading a malicious file that manipulates XML parsing to access arbitrary files on the host operating system.
This vulnerability could expose data that should remain inaccessible, even to legitimate administrators, thereby elevating the risk beyond typical configuration disclosure. Although it requires authenticated administrative access, it does not, by itself, allow for an external, unauthenticated compromise.
In many real-world deployments, ISE and ISE-PIC are integrated with identity stores, network access control, and monitoring systems, making them high-value infrastructure components. If an attacker gains administrative credentials, possibly through phishing or other means, this vulnerability allows direct access to sensitive files, including configuration data and stored secrets.
This vulnerability could enable authenticated attackers with administrative access to retrieve sensitive data from the underlying operating system.
Cisco confirms that all supported Cisco ISE and ISE-PIC releases prior to the fixed builds are affected.
Fixed releases are available, and Cisco strongly recommends upgrading, as no workarounds exist for this issue:
Earlier than 3.2: Migrate to a fixed release 3.2: 3.2 Patch 8 3.3: 3.3 Patch 8 3.4: 3.4 Patch 4 3.5: Not vulnerable
The Cisco Product Security Incident Response Team (PSIRT) reports that proof-of-concept exploit code for this vulnerability is already publicly available. While no active malicious exploitation is currently known, the presence of such code lowers the barrier for potential threats, increasing the urgency for a swift response.
Security teams are advised to limit and monitor administrative access to ISE and ISE-PIC, ensure management interfaces are protected from untrusted networks, and review authentication, MFA enforcement, and logging around ISE admin accounts. Full remediation requires upgrading to a fixed software release.
The vulnerability is associated with Cisco Bug ID CSCwq79739 and categorized under CWE-611 (Improper Restriction of XML External Entity Reference), underscoring the risks posed by improperly hardened XML parsers in critical infrastructure platforms.
Cisco acknowledges Bobby Gould of Trend Micro’s Zero Day Initiative for reporting the vulnerability. Organizations are advised to prioritize patching schedules, validate current ISE versions against Cisco’s fixed release matrix, and expedite upgrades to mitigate this vulnerability.
Based on reporting by GBHackers.
