CVE-2026-20320Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-08-19); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-08-19: 3Mentions · 2026-08-20: 2Mentions · 2026-08-22: 1Mentions · 2026-08-28: 1Mentions · 2026-09-05: 1Patch / Workaround · 2026-08-20: 2Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-19: 3Technical Details · 2026-08-20: 2Technical Details · 2026-08-22: 1Technical Details · 2026-08-28: 108-1908-2008-2208-2809-05
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-08-193
Disclosure3
2026-08-202
Patch2
2026-08-221
Patch1
2026-08-281
Patch1
2026-09-051
Disclosure1
Full discourse8 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix. #Cisco #CVE #SQLInjection #Crosswork #BroadWorks #XXE #Vulnerability #InfoSec https://securityonline.info/cisco-crosswork-cve-2026-20030/

    Post summary

    Cisco has released patches for two critical vulnerabilities: a CVSS 10.0 SQL injection in Crosswork (CVE-2026-20030) and an XXE flaw in BroadWorks (CVE-2026-20320).

    41021459
    13.0K followersView on X
  • sandesh 𓊝@onceuponahacker
    Disclosure

    My first CVE in Cisco 📸🎉 CVE-2026-20320 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt#:~:text=like%20to%20thank-,Sandesh%20M%20Gawa,-i%20for%20reporting #bugbounty #ethicalhacking

    Post summary

    The user announces their first discovered Cisco CVE, linking to the official Cisco security advisory, without additional technical or exploit details.

    00052376
    467 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة حقن كيان XML الخارجية في Cisco تسمح للمهاجمين بقراءة البيانات الحساسة 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت شركة Cisco تحديثات أمان لثغرة حقن كيان XML الخارجية عالية الخطورة في منصة BroadWorks. الثغرة (CVE-2026-20320) تتيح لمهاجم غير مصدق عن بُعد قراءة بيانات التكوين الحساسة والملفات على الأنظمة المتأثرة، وتُصنّف بدرجة CVSS 7.5. تؤثر على عدة مكونات من BroadWorks، ما قد يفضي إلى كشف معلومات داخلية. تم توجيه العملاء لتطبيق التصحيحات فوراً وتفعيل مراقبة استغلال الثغرة — يُنصح بتطبيق التصحيحات فوراً وتفعيل مراقبة استغلال الثغرة. 🗓️ تاريخ النشر: 20/08/2026 🔗 للمزيد: https://cybersecuritynews.com/?p=160173

    Post summary

    Cisco released security updates for the XML External Entity injection vulnerability (CVE‑2026‑20320) affecting BroadWorks; clients are urged to apply patches immediately.

    00040635
    437 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Cisco BroadWorks の脆弱性 CVE-2026-20320 が FIX:機密データ窃取の恐れ https://iototsecnews.jp/2026/08/20/cisco-external-entity-injection-vulnerability-allows-attackers-to-read-sensitive-data/ Cisco BroadWorks の脆弱性 CVE-2026-20320 の、修正と対策について解説する記事です。XML パーサによる外部参照制限の不備が、この件の背景です。この欠陥により、未認証での重要ファイル閲覧/構成データの流出/システム情報の非正規な取得といった被害が生じる恐れがあります。対応策として、修正適用済みリリースへの更新/管理用プロビジョニング機能のアクセス遮断/不審な外部接続の監視が求められます。 #BroadWorks #Cisco #CVE202620320 #Vulnerability

    Post summary

    The article reports on CVE‑2026‑20320, detailing its technical impact on Cisco BroadWorks and emphasizing the application of the vendor‑released fix and supplementary mitigations.

    00000143
    511 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical flaw uncovered in Cisco BroadWorks: the OCI-P service’s XML parser has an unauthenticated XXE vulnerability (CVE-2026-20320, CVSS 7.5) that could let attackers read sensitive configuration files. The issue impacts BroadWorks ADP, Profile Server, Xtended Services, and others running versions before RI.2026.07. Cisco has released the patch—immediate updates, network restrictions, and close monitoring of XML activity are essential. #Cisco #BroadWorks #XXE #Cybersecurity #CVE2026 #Infosec https://thedailytechfeed.com/critical-xxe-flaw-in-cisco-broadworks-lets-attackers-expose-configuration-files/

    Post summary

    The tweet announces a critical unauthenticated XXE vulnerability in Cisco BroadWorks (CVE-2026-20320) with a CVSS score of 7.5, explains that it allows reading config files, and informs readers that Cisco has released a patch and recommends immediate updates and monitoring.

    0000048
    652 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20320 A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration info… https://www.cve.org/CVERecord?id=CVE-2026-20320 ----- Traducción: CVE-2026-20320 Una… https://infoflow.cloud`

    Post summary

    A brief disclosure of CVE‑2026‑20320, detailing that the OCI XML Parser in Cisco BroadWorks could be exploited to read configuration data by unauthenticated remote attackers, with a link to the official CVE record.

    0000037
    100 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-20320 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-20320 #Cisco #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-20320, a high‑severity (CVSS 7.5) blind XML External Entity injection vulnerability in Cisco BroadWorks, with further details available via the provided link.

    0000043
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20320 A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration info… https://www.cve.org/CVERecord?id=CVE-2026-20320

    Post summary

    The text announces a new vulnerability (CVE-2026-20320) in Cisco BroadWorks’ OCI XML Parser that permits unauthenticated remote attackers to read sensitive configuration data.

    00000696
    58.0K followersView on X

Explore more