CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20320
Advisory Summary
ποΈ Calendar: 19 August 2026
β π¨ Cisco BroadWorks OCI Blind XXE (Out-of-Band) β High Risk Data Exposure β
π What happened
Cisco BroadWorks contains a vulnerability in the Open Client Interface (OCI) XML Parser (specifically the OCI-P service). Due to external entity resolution being allowed by default, a malicious actor can trigger a blind XML External Entity (XXE) condition to read sensitive configuration data.
- An attacker can send a crafted XML message to the Open Client Interface β Provisioning (OCI-P) service.
- The issue allows the attacker to view sensitive files on the filesystem using the privileges of the Cisco BroadWorks user.
- The advisory describes the condition as unauthenticated and remote, increasing exposure.
- High security impact (per advisory)
- Potential confidential data disclosure via filesystem read
- Exposure risk is heightened because the attacker does not require authentication.
- Cisco has released software updates to address the vulnerability.
- No workarounds are available per Ciscoβs advisory.
- CVE: CVE-2026-20320
- Vulnerability class: Blind XXE / External Entity Injection (out-of-band)
β
Recommended actions for market professionals
1. Patch immediately: verify BroadWorks version compliance with Ciscoβs fixed releases.
2. Hunt for exposure: confirm whether OCI-P endpoints are reachable from untrusted networks.
3. Detect suspicious provisioning XML traffic: look for anomalous XML payload patterns targeting provisioning interfaces.
4. Review credential sensitivity: treat disclosed filesystem artifacts (config/logs) as potentially compromised and validate any affected secrets.
- Endpoint exposure of OCI-P to the internet or broad internal networks
- Missing BroadWorks maintenance alignment / delayed hotfix adoption
- Weak monitoring around provisioning/service API traffic
-2026-20320
Reference: Vendor Advisory