ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability
ZDI detailed CVE-2026-20235, an authenticated XML external entity information disclosure flaw (CVSS 4.9) in Cisco Identity Services Engine.
ZDI-26-718 describes an XXE vulnerability in Cisco Identity Services Engine's MnTRESTLivelogService that allows remote, authenticated attackers to disclose sensitive information. The flaw is tracked as CVE-2026-20235 and carries a CVSS score of 4.9. Exploitation requires valid credentials.
- XXE in MnTRESTLivelogService enables authenticated information disclosure
- CVSS 4.9; valid credentials required to exploit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20235 | Authenticated XXE Information Disclosure in Cisco Identity Services Engine (ISE) API CVE-2026-20235 is an information-disclosure flaw in the API of Cisco Identity Services Engine (ISE), caused by insufficient validation of user-supplied parameters in API requests (CWE-89); ZDI tracks it as XML External Entity processing in the MnT REST LiveLog service. An authenticated, remote attacker who already holds valid administrative credentials can trigger it by sending a crafted API request to an affected device. A successful exploit leaks sensitive information, including hashed credentials that could be cracked or reused in follow-on attacks. Any organization running Cisco ISE that exposes the affected API to administrators is in scope; exploitation requires high privileges (PR:H), which limits practical impact. The flaw is rated 4.9 (medium), is not in CISA KEV, has no known public proof-of-concept, and there are no reports of exploitation in the wild. Do: Upgrade Cisco ISE to the fixed release listed in the Cisco PSIRT advisory for CVE-2026-20235 (fixed versions not provided in this data). As an interim mitigation, restrict access to the ISE administration portal and the MnT REST API to trusted management networks and least-privilege administrator accounts. Because hashed credentials can be harvested, review ISE API logs for unexpected or anomalous requests and rotate/monitor administrative and internal user credentials. | 4.9 | — |
| large≈20,000–50,000 enterprise/government ISE deployments worldwide (est.) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.
This source does not provide full text. Read it at zerodayinitiative.com.