What is CVE-2026-20320?
This vulnerability exists in the Open Client Interface (OCI) XML Parser of the Cisco BroadWorks platform. Due to improper handling of XML External Entities (XXE), an unauthenticated remote attacker can exploit this flaw to read sensitive configuration data from the affected system. Applying the security update provided by Cisco is strongly recommended.
Azərbaycanca: Bu zəiflik Cisco BroadWorks platformasının Open Client Interface (OCI) XML Parser komponentində aşkarlanıb. İstismar zamanı autentifikasiya olunmamış uzaqdan hücumçu External Entity (XXE) tipli hücum vasitəsilə həssas konfiqurasiya məlumatlarına icazəsiz oxuma əldə edə bilər. Cisco tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Cisco
FAQ2
In which component of the Cisco BroadWorks platform was CVE-2026-20320 discovered?
CVE-2026-20320 was discovered in the Open Client Interface (OCI) XML Parser component of the Cisco BroadWorks platform.
What impact can an attacker have by exploiting CVE-2026-20320?
An unauthenticated remote attacker can exploit this flaw via an XML External Entity (XXE) attack to gain unauthorized read access to sensitive configuration data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.