Cisco has issued critical security patches addressing a significant XML External Entity (XXE) injection vulnerability in its BroadWorks platform. This flaw, identified as CVE-2026-20320, poses a serious threat by potentially allowing unauthorized remote access to sensitive configuration data.
Details of the Cisco Vulnerability
The vulnerability, which is present in the Open Client Interface XML Parser, is categorized under CWE-611, denoting an improper restriction of XML external entity references. Cisco disclosed this security issue in advisory cisco-sa-bworks-xxe-uwUd7CEt on August 19, 2026, attributing it a CVSS score of 7.5, indicating high severity.
The root cause of the flaw lies in the XML parser’s default behavior of resolving external entities, which can inadvertently allow attackers to access local resources or other restricted data through carefully crafted XML messages.
Impact and Exploitation Risks
This vulnerability is notably concerning because it does not require authentication or user interaction to be exploited. Attackers can potentially exploit this flaw by sending malicious XML messages to the Open Client Interface Provisioning service (OCI-P), risking exposure of sensitive files.
The flaw affects several components within the BroadWorks platform, including the Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform. Systems running releases earlier than RI.2026.07 are vulnerable, but Cisco has provided a remedy in the RI.2026.07 release and recommends immediate upgrading.
Mitigation and Security Recommendations
Given the absence of viable workarounds, Cisco advises customers to upgrade to the fixed software release without delay. The company also emphasizes the importance of reviewing network configurations to minimize exposure. OCI-P should be isolated from untrusted networks via robust firewall rules and network segmentation.
Monitoring efforts should focus on detecting unusual XML activity and unauthorized outbound connections from BroadWorks infrastructure, which could indicate attempted exploitation. Cisco’s Product Security Incident Response Team (PSIRT) has reported no known exploitation attempts or public disclosures of this vulnerability thus far.
Organizations are urged to act swiftly to safeguard their systems, leveraging these patches to bolster their cybersecurity defenses effectively.
