Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt Security Impact Rating: High CVE: CVE-2026-20320
CSIRTS triage
- What
- Out-of-band blind XML external entity injection in the OCI XML Parser allows unauthenticated remote attackers to read sensitive configuration files.
- Who is affected
- Cisco BroadWorks deployments with OCI-P service enabled are affected.
- Urgency
- High urgency; remote unauthenticated exploitation allows exposure of sensitive filesystem information.
- Action
- Apply Cisco BroadWorks software updates addressing CVE-2026-20320.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch BroadWorks
Get an email when a new BroadWorks advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-203200.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20320 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19