Cisco BroadWorks Vulnerability Exposes Sensitive Configuration Files
Cisco has issued security updates for a high-severity vulnerability in its BroadWorks platform, which allows unauthenticated remote attackers to access sensitive configuration files on affected systems.
The vulnerability, tracked as CVE-2026-20320, is an out-of-band blind XML External Entity (XXE) injection flaw in the Open Client Interface (OCI) XML Parser.
Cisco assigned a CVSS score of 7.5 out of 10 to this issue, indicating its potential for network exploitation and low attack complexity.
According to Cisco's advisory, the vulnerability arises from improper parsing of XML entries within the BroadWorks OCI environment.