CVE-2026-20320

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.

Severity
High 7.5
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.005
40.3th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 19, 2026
Assigned by cisco

Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Weakness: CWE-611

Affected products

Vendor Product Category Matched by
Cisco Cisco BroadWorks Other Products cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco BroadWorks

Vendor advisory

cisco-sa-bworks-xxe-uwUd7CEt

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

Cisco’s rating: High (advisory CVSS 7.5) · Published Aug 19, 2026

Bug ID: CSCwv48590

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?