ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI publishes three Cisco Identity Services Engine advisories: two authenticated RCE flaws and one XXE information disclosure” — merged summary and timeline →

ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

lowAdvisoryimportance 20CVE-2026-20235
AI summary · glm-5.3-flash

ZDI detailed CVE-2026-20235, an authenticated XML external entity information disclosure flaw (CVSS 4.9) in Cisco Identity Services Engine.

ZDI-26-718 describes an XXE vulnerability in Cisco Identity Services Engine's MnTRESTLivelogService that allows remote, authenticated attackers to disclose sensitive information. The flaw is tracked as CVE-2026-20235 and carries a CVSS score of 4.9. Exploitation requires valid credentials.

  • XXE in MnTRESTLivelogService enables authenticated information disclosure
  • CVSS 4.9; valid credentials required to exploit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20235
Authenticated XXE Information Disclosure in Cisco Identity Services Engine (ISE) API

CVE-2026-20235 is an information-disclosure flaw in the API of Cisco Identity Services Engine (ISE), caused by insufficient validation of user-supplied parameters in API requests (CWE-89); ZDI tracks it as XML External Entity processing in the MnT REST LiveLog service. An authenticated, remote attacker who already holds valid administrative credentials can trigger it by sending a crafted API request to an affected device. A successful exploit leaks sensitive information, including hashed credentials that could be cracked or reused in follow-on attacks. Any organization running Cisco ISE that exposes the affected API to administrators is in scope; exploitation requires high privileges (PR:H), which limits practical impact. The flaw is rated 4.9 (medium), is not in CISA KEV, has no known public proof-of-concept, and there are no reports of exploitation in the wild.

Do: Upgrade Cisco ISE to the fixed release listed in the Cisco PSIRT advisory for CVE-2026-20235 (fixed versions not provided in this data). As an interim mitigation, restrict access to the ISE administration portal and the MnT REST API to trusted management networks and least-privilege administrator accounts. Because hashed credentials can be harvested, review ISE API logs for unexpected or anomalous requests and rotate/monitor administrative and internal user credentials.

4.9
  • Cisco Identity Services Engine (ISE) — API / MnT REST LiveLog service (MnTRESTLivelogService)
large≈20,000–50,000 enterprise/government ISE deployments worldwide (est.)
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

This source does not provide full text. Read it at zerodayinitiative.com.