PT-2026-78521 · Cisco · Broadworks

CVE-2026-20320

·

Published

2026-08-19

·

Updated

2026-09-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco BroadWorks (affected versions not specified)
Description An issue in the Open Client Interface (OCI) XML Parser allows an unauthenticated remote attacker to read sensitive configuration information. This occurs because the parser improperly handles XML entries by allowing external entity resolution by default. An attacker can exploit this by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service, potentially enabling the viewing of sensitive filesystem files with the privileges of the Cisco BroadWorks user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20320

Affected Products

Broadworks