
[CIVN-2026-0417] Out-of-Band Blind XML External Entity Injection Vulnerability in Cisco BroadWorks
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Out-of-Band Blind XML External Entity Injection Vulnerability in Cisco BroadWorks
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
BroadWorks Application Delivery Platform: Earlier than RI.2026.07
BroadWorks Application Server: Earlier than RI.2026.07
BroadWorks Profile Server: Earlier than RI.2026.07
BroadWorks Xtended Services Platform: Earlier than RI.2026.07
Overview
A vulnerability has been reported in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks which could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.
Target Audience:
All organizations and individuals using Cisco BroadWorks.
Risk Assessment:
High risk of unauthorized disclosure of sensitive configuration information.
Impact Assessment:
Potential for an attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.
Description
Cisco BroadWorks is a platform that provides various telecommunications services through components such as the Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform.
These vulnerabilities exist in the Open Client Interface (OCI) XML Parser due to improper parsing of XML entries, as external entity resolution is allowed by default.
A successful exploit could allow an unauthenticated, remote attacker to send a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.
Solution
Apply appropriate updates as mentioned:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt#fs
Vendor Information
https://www.cisco.com/c/en/us/products/unified-communications/broadworks/index.html
References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt#fs
CVE Name
CVE-2026-20320
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqIdH8ACgkQ3jCgcSdc
ys+W5g/+Mvz8UjK+3yMNn6CrocKnWnYCZJhnWLRkHBmvWjVVL4zOJGVy19OmWLd8
RB1saw2rxFa1hCBTTHvP6dZmeuQV6Y9xYru0nIV7xIte11RCJ2qcFuxWZvHypLGc
kGmkJHC5QX4P9fbBJWwPEyntE2o7ZIzLSX9sPFLY9lbExcxYj+B9zsDeOONZnwNQ
0q6fU6buWPdbVs+dcRc8Xu06o/cD5pcDdLcez0FDbqfIW7F5ROTv02I1UpbjuXxE
EZLc5l/a5RPV6ynnGDqeCKA1gxJAU7Wr/N1eDGV7QfFktl2LfE/gY90kENz5RYfm
C+QG9Kaan2BLoaIvOHd8+obyaxsJBjeFEqHVX9pKe2OFuiPSy62mw0wfviwyD3y5
yDO82ifB2ifmS5reEw4TcKnNZok7CjljPZZim6huYapJIEcic95M5mLy+FTueVx8
ObMfhcM+Hzarpq7uP/0RwBYLH8YB2TZpM0jxzwDZqmn8OL6++M5zZNrasC+SqQdX
jAxGVsMvn1rJ23e6MUdZrE2OhQX7gjK7JsHH3xIbYVY9yU6OptEnyz3HgS11zFTa
N+oGGMJMiADDx7TYPuSWL3cq6iCWA9akl5JCpSnmnU6u2lhOIPRz8Cjvlxm5CFtG
Qtg54uDz3u8cu4BZfwztg/mLuSfqcXb+BPoEhgwgVK6Yb0mtpNI=
=dzHu
—–END PGP SIGNATURE—–


