XML Parsing Flaw in Cisco BroadWorks Allowing Unauthorized Information Disclosure
CVE-2026-20320
7.5HIGH
What is CVE-2026-20320?
A security issue in Cisco BroadWorks' Open Client Interface (OCI) XML Parser allows unauthenticated remote attackers to access sensitive configuration details. This vulnerability arises from improper parsing of XML entries, which permits external entity resolution by default. Attackers can exploit it by crafting malicious XML messages directed at the OCI-P service, potentially revealing sensitive filesystem data with the privileges of the BroadWorks user.
Affected Version(s)
Cisco BroadWorks