CVE-2026-20320: A high-severity External Entity Injection flaw in Cisco BroadWorks XML

24 Aug 2026

Cisco released an advisory on August 19 regarding a high-severity vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks that allowed an unauthenticated remote attacker to read sensitive information on an affected system.

 

Through this blog, we will understand what the vulnerability is about, the threat it poses, and what organizations should do to defend.

About the vulnerabilities

Vendor + components affected 

CVE/CVSS 

About  

Discovery    

 

Cisco +  

BroadWorks Open Client Interface (OCI) XML Parser/ OCI-P 

(Open Client Interface Provisioning) 

CVE-2026-20320 / 7.5 (High) 

 

Impact – Sensitive information  

 

Disclosure 

Authentication- Not required 

 

 

Attack vector – Network  

 

Attack complexity – Low 

 

Technical issue – XML External Entity Injection (CWE-611) 

 

 

 

August 19, 2026 

Affected systems

Cisco has identified the following products as affected when running a release earlier than the fixed release:

  • BroadWorks Application Delivery Platform
  • BroadWorks Application Server
  • BroadWorks Profile Server
  • BroadWorks Xtended Services Platform

 

Affected version – earlier than RI.2026.07

 

First fixed release – RI.2026.07

 

The vulnerability should be prioritized because it is:

 

  • Remotely exploitable.
  • Unauthenticated.
  • Low complexity.
  • Capable of exposing sensitive filesystem information.
  • Present in telecommunications infrastructure.
  • Associated with an XML parser weakness that may be attractive for automated exploitation.

The threat posed by the vulnerability

Cisco has warned that the vulnerability can be exploited by an attacker to access confidential information.

 

It is important for telecommunications providers and organizations that use BroadWorks infrastructure to fix the flaw because it can allow attackers to access sensitive service configuration and other information.

 

An attacker can exploit the vulnerability to:

 

  • Read sensitive files from the affected BroadWorks filesystem.
  • Access information available in the Cisco BroadWorks service account.
  • Obtain sensitive configuration information.
  • Obtain credentials, tokens, keys, or other sensitive information if such data is accessible to the affected service account.
  • Support other attacks using the disclosed configuration information.
  • Use information obtained to cause a compromise of telecommunications infrastructure.
  • Target remotely accessible BroadWorks OCI-P services without requiring valid credentials.

SharkStriker’s recommendations

  • Prioritize CVE-2026-20320 for remediation on all affected Cisco BroadWorks deployments.
  • Identify all Cisco BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform instances.
  • Determine the exact BroadWorks software release running on each system.
  • Identify systems running a release earlier than RI.2026.07.
  • Upgrade affected systems to RI.2026.07 or later.
  • Pay particular attention to systems exposing the OCI-P service to untrusted or externally reachable networks.
  • Restrict access to OCI-P and related management/provisioning interfaces to trusted administrative or service networks where operationally feasible.
  • Avoid exposing BroadWorks provisioning interfaces directly to the public Internet unless required and appropriately protected.
  • Review firewall and network-access-control rules governing access to BroadWorks OCI services.
  • Monitor BroadWorks logs for unusual or malformed XML requests and unexpected OCI-P activity.
  • Review the filesystem and configuration areas accessible to the BroadWorks service account.
  • Rotate credentials, keys, or other secrets if there is evidence that sensitive configuration files may have been accessed.
  • Validate the software version after remediation.

SharkStriker’s action

  • Threat intelligence profile reviewed.
  • CVE-2026-20320 assessed for severity and customer relevance.
  • Cisco BroadWorks identified as the affected product family.
  • Open Client Interface (OCI) XML Parser identified as the affected component.
  • OCI-P (Open Client Interface – Provisioning) identified as the attack surface described by Cisco.
  • XML External Entity Injection identified as the underlying technical vulnerability.
  • CWE-611 identified as the applicable weakness classification.
  • Unauthorized sensitive filesystem access identified as the primary security impact.
  • Cisco fixed release RI.2026.07 identified.
  • Cisco’s statement regarding the absence of known public exploitation or malicious use reviewed.
  • No workaround identified; software upgrade determined to be the primary remediation.
  • BroadWorks systems running releases earlier than RI.2026.07 identified as requiring remediation.
  • Internet-accessible or untrusted-network-accessible OCI-P services identified as priority assets for assessment.
  • Customers operating affected Cisco BroadWorks versions advised to prioritize remediation.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE