Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4344 articles · 196297 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-20320
Cisco · Cisco BroadWorks

CVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote

Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Affected Products

VendorProductVersions
CiscoCisco BroadWorksN/A

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt

Related News (2 articles)

Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Cisco (20 août 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-20320 | Cisco BroadWorks XML Parser information disclosure
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-611
PublishedAug 19, 2026
Last enriched4d ago
Trending Score30
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 31
HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 31
MEDIUMCVE-2026-20232
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Trending: 21
MEDIUMCVE-2026-20302
Cisco RoomOS Stack Overflow Vulnerability
Trending: 16
HIGHCVE-2026-20339
ClamAV PESpin File Format Processing Integer Overflow Vulnerability
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 19, 2026
Discovered by ZDM
Aug 19, 2026