---
id: CVE-2026-76446
title: "A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&nbsp;files on the underlying operating system of an affected device.\r\n\r\nThis vulnerability is due to improper restric…"
summary: "A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&nbsp;files on the underlying operating system of an affected device.\r\n\r\nThis vulnerability is due to improper restric…"
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-611
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.1.0
  - identity_services_engine_software 3.1.0 p1
  - identity_services_engine_software 3.1.0 p3
  - identity_services_engine_software 3.1.0 p2
  - identity_services_engine_software 3.2.0
  - identity_services_engine_software 3.1.0 p4
  - identity_services_engine_software 3.1.0 p5
  - identity_services_engine_software 3.2.0 p1
  - identity_services_engine_software 3.1.0 p6
  - identity_services_engine_software 3.2.0 p2
  - identity_services_engine_software 3.1.0 p7
  - identity_services_engine_software 3.3.0
  - identity_services_engine_software 3.2.0 p3
  - identity_services_engine_software 3.2.0 p4
  - identity_services_engine_software 3.1.0 p8
  - identity_services_engine_software 3.2.0 p5
  - identity_services_engine_software 3.2.0 p6
  - identity_services_engine_software 3.1.0 p9
  - identity_services_engine_software 3.3 Patch 2
  - identity_services_engine_software 3.3 Patch 1
  - identity_services_engine_software 3.3 Patch 3
  - identity_services_engine_software 3.4.0
  - identity_services_engine_software 3.2.0 p7
  - identity_services_engine_software 3.3 Patch 4
  - identity_services_engine_software 3.4 Patch 1
  - identity_services_engine_software 3.1.0 p10
  - identity_services_engine_software 3.3 Patch 5
  - identity_services_engine_software 3.3 Patch 6
  - identity_services_engine_software 3.4 Patch 2
  - identity_services_engine_software 3.3 Patch 7
  - identity_services_engine_software 3.4 Patch 3
  - identity_services_engine_software 3.5.0
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.3 Patch 8
  - identity_services_engine_software 3.2 Patch 8
  - identity_services_engine_software 3.5 Patch 1
  - identity_services_engine_software 3.3 Patch 9
  - identity_services_engine_software 3.2 Patch 9
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.5 Patch 2
  - identity_services_engine_software 3.3 Patch 10
  - identity_services_engine_software 3.3 Patch 11
  - identity_services_engine_software 3.4 Patch 6
  - identity_services_engine_software 3.2 Patch 10
  - identity_services_engine_software 3.1.0 p72
  - identity_services_engine_software 3.1.0 p11
  - ise_passive_identity_connector 3.2.0
  - ise_passive_identity_connector 3.1.0
  - ise_passive_identity_connector 3.3.0
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:28:28.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76446'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
epss: 0.00513
epssPercentile: 0.41165
ingestedAt: '2026-09-16T16:37:52.180Z'
---

## Overview

A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&nbsp;files on the underlying operating system of an affected device.

This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read specific&nbsp;files on the affected system that the underlying process has permission to access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ise-multiauth-bypass-sgD2HbL4** · Cisco · affected: Cisco ISE Passive Identity Connector (4 versions), Cisco Identity Services Engine Software (46 versions) · updated 2026-09-24 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4)
