High severity7.5NVD Advisory· Published Aug 19, 2026· Updated Aug 20, 2026
CVE-2026-20320
CVE-2026-20320
Description
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
3- Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive DataCyber Security News · Aug 20, 2026
- Cisco Patches Critical Crosswork, Secure Workload VulnerabilitiesSecurityWeek · Aug 20, 2026
- Cisco Systems: 18 Vulnerabilities Disclosed, Including Five Critical Flaws in Crosswork and Secure WorkloadVypr Intelligence · Aug 19, 2026