Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Brief
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems.
Tracked as CVE-2026-20320, the issue carries a CVSS score of 7. 5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified as CWE-611, or improper restriction of XML external entity reference.
Cisco published the advisory, cisco-sa-bworks-xxe-uwUd7CEt, on August 19, 2026. Cisco said the flaw exists because the affected XML parser allows external entity resolution by default.
When XML input is processed, external entities can instruct the parser to retrieve local resources or access other available locations.
