Cisco BroadWorks Vulnerability Exposes Sensitive Data to Remote Attackers
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems.
The issue, tracked as CVE-2026-20320, carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. It exists because the affected XML parser allows external entity resolution by default.
An attacker could exploit the vulnerability by sending a specially crafted XML message to the Open Client Interface Provisioning service, also known as OCI-P. Successful exploitation does not require authentication or user interaction, increasing the risk for exposed or reachable BroadWorks deployments.