[CIVN-2026-0417] Out-of-Band Blind XML External Entity Injection Vulnerability in Cisco BroadWorks

By Published On: August 21, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Out-of-Band Blind XML External Entity Injection Vulnerability in Cisco BroadWorks


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


BroadWorks Application Delivery Platform: Earlier than RI.2026.07

BroadWorks Application Server: Earlier than RI.2026.07

BroadWorks Profile Server: Earlier than RI.2026.07

BroadWorks Xtended Services Platform: Earlier than RI.2026.07

Overview


A vulnerability has been reported in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks which could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.


Target Audience:

All organizations and individuals using Cisco BroadWorks.


Risk Assessment:

High risk of unauthorized disclosure of sensitive configuration information.


Impact Assessment:

Potential for an attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.


Description


Cisco BroadWorks is a platform that provides various telecommunications services through components such as the Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform.


These vulnerabilities exist in the Open Client Interface (OCI) XML Parser due to improper parsing of XML entries, as external entity resolution is allowed by default.


A successful exploit could allow an unauthenticated, remote attacker to send a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.


Solution


Apply appropriate updates as mentioned:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt#fs



Vendor Information


 

https://www.cisco.com/c/en/us/products/unified-communications/broadworks/index.html


References


 

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt#fs


CVE Name

CVE-2026-20320




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqIdH8ACgkQ3jCgcSdc

ys+W5g/+Mvz8UjK+3yMNn6CrocKnWnYCZJhnWLRkHBmvWjVVL4zOJGVy19OmWLd8

RB1saw2rxFa1hCBTTHvP6dZmeuQV6Y9xYru0nIV7xIte11RCJ2qcFuxWZvHypLGc

kGmkJHC5QX4P9fbBJWwPEyntE2o7ZIzLSX9sPFLY9lbExcxYj+B9zsDeOONZnwNQ

0q6fU6buWPdbVs+dcRc8Xu06o/cD5pcDdLcez0FDbqfIW7F5ROTv02I1UpbjuXxE

EZLc5l/a5RPV6ynnGDqeCKA1gxJAU7Wr/N1eDGV7QfFktl2LfE/gY90kENz5RYfm

C+QG9Kaan2BLoaIvOHd8+obyaxsJBjeFEqHVX9pKe2OFuiPSy62mw0wfviwyD3y5

yDO82ifB2ifmS5reEw4TcKnNZok7CjljPZZim6huYapJIEcic95M5mLy+FTueVx8

ObMfhcM+Hzarpq7uP/0RwBYLH8YB2TZpM0jxzwDZqmn8OL6++M5zZNrasC+SqQdX

jAxGVsMvn1rJ23e6MUdZrE2OhQX7gjK7JsHH3xIbYVY9yU6OptEnyz3HgS11zFTa

N+oGGMJMiADDx7TYPuSWL3cq6iCWA9akl5JCpSnmnU6u2lhOIPRz8Cjvlxm5CFtG

Qtg54uDz3u8cu4BZfwztg/mLuSfqcXb+BPoEhgwgVK6Yb0mtpNI=

=dzHu

—–END PGP SIGNATURE—–

Share this article