Skip to content
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Ground.News August 20, 2026

Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems. Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified …

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.

Important security updates have been released for Cisco BroadWorks, Crosswork Security and Secure Workload.

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage