Cisco Patches High-Severity XXE Vulnerability in BroadWorks Platform
Cisco has released security updates to address a high-severity XML External Entity (XXE) injection vulnerability (CVE-2026-20320) in its BroadWorks platform, which could allow unauthenticated remote attackers to access sensitive configuration data and files. The flaw, assigned a CVSS score of 7.5, stems from improper restrictions in the Open Client Interface XML Parser (CWE-611), enabling external entity resolution by default.
Exploitation requires no authentication or user interaction, increasing risk for exposed BroadWorks deployments. Attackers could send crafted XML messages to the Open Client Interface Provisioning (OCI-P) service to extract filesystem data under the permissions of the BroadWorks user. The vulnerability is classified as an out-of-band blind XXE, where attackers may not receive direct responses but can induce the server to transmit data to an external system.
Affected products include the BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform, specifically versions prior to RI.2026.07. Cisco has patched the issue in the RI.2026.07 release, with fixes applied to the Open Client Server and OCIOverSoap components. No workaround exists, and Cisco advises upgrading to the fixed release while restricting OCI-P access via network segmentation and firewall policies.
Security teams are encouraged to monitor for unusual XML requests, unexpected outbound connections, and unauthorized file access attempts. As of the advisory’s publication on August 19, 2026, Cisco reported no known public exploitation or disclosure. The vulnerability was reported by security researcher Sandesh M Gawai.
Source: https://cybersecuritynews.com/cisco-external-entity-injection-vulnerability/
Cisco TPRM report: https://www.rankiteo.com/company/cisco
"id": "cis1787228649",
"linkid": "cisco",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Networking',
'name': 'Cisco',
'type': 'Corporation'}],
'attack_vector': 'Remote',
'data_breach': {'data_exfiltration': 'Possible (out-of-band blind XXE)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive configuration data and '
'files'},
'date_publicly_disclosed': '2026-08-19',
'description': 'Cisco has released security updates to address a '
'high-severity XML External Entity (XXE) injection '
'vulnerability (CVE-2026-20320) in its BroadWorks platform, '
'which could allow unauthenticated remote attackers to access '
'sensitive configuration data and files. The flaw stems from '
'improper restrictions in the Open Client Interface XML Parser '
'(CWE-611), enabling external entity resolution by default. '
'Exploitation requires no authentication or user interaction, '
'increasing risk for exposed BroadWorks deployments. Attackers '
'could send crafted XML messages to the Open Client Interface '
'Provisioning (OCI-P) service to extract filesystem data under '
'the permissions of the BroadWorks user. The vulnerability is '
'classified as an out-of-band blind XXE, where attackers may '
'not receive direct responses but can induce the server to '
'transmit data to an external system.',
'impact': {'data_compromised': 'Sensitive configuration data and files',
'systems_affected': 'BroadWorks Application Delivery Platform, '
'Application Server, Profile Server, and '
'Xtended Services Platform'},
'investigation_status': 'Patched',
'post_incident_analysis': {'corrective_actions': 'Patches applied to the Open '
'Client Server and '
'OCIOverSoap components in '
'RI.2026.07 release',
'root_causes': 'Improper restrictions in the Open '
'Client Interface XML Parser '
'(CWE-611), enabling external '
'entity resolution by default'},
'recommendations': 'Upgrade to the fixed release (RI.2026.07), restrict OCI-P '
'access via network segmentation and firewall policies, '
'and monitor for unusual XML requests and unauthorized '
'file access attempts.',
'references': [{'source': 'Cisco Security Advisory'}],
'response': {'containment_measures': 'Cisco advises upgrading to the fixed '
'release (RI.2026.07) and restricting '
'OCI-P access via network segmentation '
'and firewall policies',
'enhanced_monitoring': 'Recommended (monitor for unusual XML '
'requests, unexpected outbound '
'connections, and unauthorized file '
'access attempts)',
'network_segmentation': 'Recommended',
'remediation_measures': 'Patches applied to the Open Client '
'Server and OCIOverSoap components in '
'RI.2026.07 release'},
'title': 'Cisco Patches High-Severity XXE Vulnerability in BroadWorks '
'Platform',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-20320 (XXE Injection, CWE-611)'}