Junglewise Threat Intelligence

CVE-2026-20320: Cisco BroadWorks XXE injection in OCI XML parser

CVE-2026-20320 · Severity: high · CVSS 7.5 · Published 2026-08-19

Executive brief

Cisco BroadWorks is a telecommunications platform used by service providers to deliver voice, messaging, and collaboration services to enterprise and consumer customers. An unauthenticated attacker can exploit an XML parsing flaw to read sensitive configuration files and data from the affected system by sending a specially crafted message to the provisioning service, potentially exposing credentials and system details that could lead to further compromise.

Technical details

This is an XML External Entity (XXE) injection vulnerability (CWE-611) in the Open Client Interface (OCI) XML Parser component of Cisco BroadWorks. The root cause is that XML external entity resolution is enabled by default, allowing an attacker to craft malicious XML messages that reference external entities. An unauthenticated remote attacker can send a crafted XML message to the OCI-Provisioning (OCI-P) service over the network without any authentication or user interaction. Successful exploitation allows the attacker to read arbitrary files from the filesystem with the privileges of the Cisco BroadWorks process. Patches are available in RI.2026.07 and later releases for all affected products.

Affected products

  • Cisco BroadWorks Application Delivery Platform earlier than RI.2026.07
  • Cisco BroadWorks Application Server earlier than RI.2026.07
  • Cisco BroadWorks Profile Server earlier than RI.2026.07
  • Cisco BroadWorks Xtended Services Platform earlier than RI.2026.07

Timeline

  • 2026-08-19: disclosed: Vulnerability publicly disclosed by Cisco PSIRT
  • 2026-08-19: patched: Fixed in RI.2026.07 for all affected products

References

Related threats