HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

CVE‑2026‑20235: XML External Entity (XXE) Information Disclosure in Cisco Identity Services Engine (ISE)

Cisco ISE’s MnTRESTLivelogService suffers an XXE processing flaw (CVE‑2026‑20235) that lets authenticated attackers pull sensitive data. The issue underscores the importance of documented vulnerability remediation for audit readiness.

Verisq™ Intelligence · 📅 September 19, 2026 · 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

CVE‑2026‑20235: XML External Entity (XXE) Information Disclosure in Cisco Identity Services Engine (ISE)

What It Is — Cisco Identity Services Engine (ISE) contains an XML External Entity (XXE) processing flaw in the MnTRESTLivelogService class that can be leveraged by authenticated remote attackers to retrieve sensitive data.

Exploitability — Requires valid authentication; no public exploit code is known, but the vulnerability is rated CVSS 4.9 (Moderate) and Cisco has released a patch.

Affected Products — Cisco Identity Services Engine (all versions vulnerable to CVE‑2026‑20235).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability management evidence to prove timely remediation.
  • Highlights gaps in secure configuration controls—specifically XML parsing hardening—that map to multiple frameworks (e.g., NIST CSF, ISO 27001).
  • Provides a concrete data‑leakage scenario that auditors will scrutinize when assessing data protection and audit‑ready postures.

Recommended Actions

  1. Deploy Cisco’s security update for ISE immediately.
  2. Verify remediation by scanning for the patched version and confirming the XXE vector is blocked.
  3. Record the patch‑deployment as control evidence in your Trust Center or similar audit repository.
  4. Update your vulnerability‑management process to include XML parser hardening checks for future releases.

Source: Zero Day Initiative Advisory – ZDI‑26‑718

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-718/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →