Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196335 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-20320
Cisco · Cisco BroadWorks

CVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote

Description

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Affected Products

VendorProductVersions
CiscoCisco BroadWorksN/A

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt

Related News (2 articles)

Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Cisco (20 août 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-20320 | Cisco BroadWorks XML Parser information disclosure
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-611
PublishedAug 19, 2026
Last enriched4d ago
Trending Score29
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 30
HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 30
MEDIUMCVE-2026-20232
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Trending: 21
MEDIUMCVE-2026-20302
Cisco RoomOS Stack Overflow Vulnerability
Trending: 15
CRITICALCVE-2026-20303
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 19, 2026
Discovered by ZDM
Aug 19, 2026