Authenticated XXE Information Disclosure in Cisco Identity Services Engine (ISE) API
AI analysis
CVE-2026-20235 is an information-disclosure flaw in the API of Cisco Identity Services Engine (ISE), caused by insufficient validation of user-supplied parameters in API requests (CWE-89); ZDI tracks it as XML External Entity processing in the MnT REST LiveLog service. An authenticated, remote attacker who already holds valid administrative credentials can trigger it by sending a crafted API request to an affected device. A successful exploit leaks sensitive information, including hashed credentials that could be cracked or reused in follow-on attacks. Any organization running Cisco ISE that exposes the affected API to administrators is in scope; exploitation requires high privileges (PR:H), which limits practical impact. The flaw is rated 4.9 (medium), is not in CISA KEV, has no known public proof-of-concept, and there are no reports of exploitation in the wild.
What to do: Upgrade Cisco ISE to the fixed release listed in the Cisco PSIRT advisory for CVE-2026-20235 (fixed versions not provided in this data). As an interim mitigation, restrict access to the ISE administration portal and the MnT REST API to trusted management networks and least-privilege administrator accounts. Because hashed credentials can be harvested, review ISE API logs for unexpected or anomalous requests and rotate/monitor administrative and internal user credentials.
Affected
| Cisco Identity Services Engine (ISE) — API / MnT REST LiveLog service (MnTRESTLivelogService) | — |
Estimated exposure
large≈20,000–50,000 enterprise/government ISE deployments worldwide (est.) — Cisco ISE is the market-leading enterprise network access control platform, deployed by tens of thousands of large organizations typically as dedicated appliance clusters; only a small fraction of admin/API interfaces are internet-facing,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.