Cisco BroadWorks XXE Flaw Allows Unauthenticated Remote File Disclosure
Brief
Cisco has released security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to disclose sensitive configuration information from affected systems.
Tracked as CVE-2026-20320, the issue is an out-of-band blind XML External Entity (XXE) injection flaw in the Open Client Interface (OCI) XML parser and carries a CVSS score of 7.5 out of 10.
Cisco describes the vulnerability as network-exploitable, requiring neither authentication nor user interaction.
Cisco BroadWorks XXE Flaw
The flaw affects BroadWorks environments where the vulnerable OCI parsing behavior is present, making rapid exposure assessment important for service providers and enterprises operating the platform.
The vulnerability stems from improper parsing of XML entries in the Cisco BroadWorks OCI environment.
