SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-20320

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in Cisco BroadWorks' Open Client Interface (OCI) XML Parser allows unauthenticated remote attackers to exploit improper XML parsing, enabling them to read sensitive configuration files from the system. This could lead to unauthorized access to critical information with the privileges of the Cisco BroadWorks user. Organizations using Cisco BroadWorks should prioritize addressing this vulnerability to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20320
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Cisco

Original NVD Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.