CVE-2026-20320
Received Received - Intake

Cisco BroadWorks OCI XML Parser Information Disclosure

Vulnerability report for CVE-2026-20320, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco broadworks ri.2026.07
cisco broadworks *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an XML External Entity Injection vulnerability in Cisco BroadWorks. It allows unauthenticated remote attackers to read sensitive configuration information because the XML parser permits external entity resolution by default. Attackers can exploit this by sending a crafted XML message to the Open Client Interface Provisioning service.

Detection Guidance

Detecting this vulnerability requires checking if the Cisco BroadWorks OCI-P service is exposed and if XML parsing allows external entity resolution. Inspect network traffic for XML messages sent to OCI-P ports (default 2208). Use tools like Wireshark to analyze XML payloads for crafted content. Verify server configurations to ensure XML external entity processing is disabled.

Impact Analysis

An attacker could exploit this to view sensitive files on the filesystem with the privileges of the Cisco BroadWorks user. This may include configuration data or other confidential information, potentially leading to further attacks or data exposure.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by exposing sensitive configuration information and filesystem data. Unauthorized access to such data may lead to breaches of confidentiality requirements under these regulations.

Mitigation Strategies

Immediately upgrade Cisco BroadWorks to fixed releases like RI.2026.07 or later. Disable XML external entity resolution in the OCI-P service configuration. Restrict network access to OCI-P ports (e.g., 2208) to trusted sources only. Monitor for unusual XML traffic patterns or unauthorized file access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20320. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart