Vulnerabilities
Cisco BroadWorks XML Parser Vulnerability (CVE‑2026‑20320) Enables Remote File Disclosure
A flaw in Cisco BroadWorks’ Open Client Interface XML parser lets unauthenticated attackers send crafted messages to the OCI‑P service and retrieve sensitive configuration files. The issue stems from default external entity resolution, enabling a blind XML External Entity (XXE) injection. Cisco has issued patches; no work‑arounds exist. Systems running BroadWorks should apply the update immediately.
A new security advisory from Cisco reveals a high‑impact flaw in the Open Client Interface (OCI) XML parser used by BroadWorks. The vulnerability, identified as CVE‑2026‑20320, allows an unauthenticated, remote attacker to craft an XML payload that exploits the parser’s default external entity resolution. The result is a blind XML External Entity (XXE) injection that can read arbitrary files on the BroadWorks server with the same privileges as the BroadWorks service account.
Attackers would target the OCI‑P (Provisioning) service by sending the malicious XML message over the network. If successful, the attacker could pull sensitive configuration files or other data from the filesystem, potentially exposing critical network settings or credentials.
Cisco has released software updates that fix the parsing logic and disable external entity resolution by default. No interim work‑arounds are available, so applying the patch is the only mitigation. BroadWorks deployments should verify that the latest firmware is installed and monitor for any anomalous OCI traffic.
Organizations using Cisco BroadWorks should act quickly to update their systems and review access controls around the OCI interface to reduce exposure to similar XML‑based attacks in the future.