ZeroHour

CVE-2026-20320

mass

Unauthenticated XXE File Read in Cisco BroadWorks OCI-P Service

CVSS 3.1
7.5 high
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-20320 is an XML External Entity (XXE) flaw (CWE-611) in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks, where external entity resolution is allowed by default and XML entries are improperly parsed. An unauthenticated remote attacker triggers it by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service on an affected system. A successful exploit lets the attacker view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user; confidentiality is impacted, with no integrity or availability effect (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). Only BroadWorks deployments whose OCI-P interface is reachable by the attacker are exposed, and the scope of affected releases is defined by Cisco's advisory. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation within 30 days, indicating low near-term exploitation risk.

What to do: Upgrade affected BroadWorks systems to the fixed releases listed in the Cisco security advisory published August 19, 2026. Until patching, restrict network access to the OCI-P interface with firewall or ACL rules so only trusted provisioning systems can reach it, and audit whether OCI-P is exposed to the internet or shared networks. Monitor Cisco PSIRT for updates, as no public PoC exists yet but pre-authentication makes internet-exposed deployments the priority.

Affected
Cisco BroadWorks (Open Client Interface XML Parser / OCI-P service)
Estimated exposure
massLikely thousands to tens of thousands of BroadWorks server deployments serving millions of subscribers via hundreds of service providers; the directly… — Cisco BroadWorks is one of the most widely deployed hosted-VoIP/UC platforms among telecom service providers, implying a mass-scale subscriber base, but the flaw is only exploitable where the OCI-P provisioning interface is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.