In plain language
What this advisory means
Cisco BroadWorks has a security flaw in the way it processes XML data, which could let an attacker who isn't logged in read sensitive system files. This happens because the system by default allows external references in XML files, which can be exploited by sending specially crafted messages. Cisco has released software updates to fix this issue. There is no workaround available to prevent this problem, so updating is necessary.
Technical explanation
How the issue affects the environment
The vulnerability exists in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks, where it improperly parses XML entries by allowing external entity resolution by default. An unauthenticated remote attacker can exploit this by sending a crafted XML message to the Open Client Interface - Provisioning (OCI-P) service, resulting in out-of-band blind XML External Entity (XXE) Injection. This allows the attacker to read sensitive filesystem files with the privileges of the Cisco BroadWorks user. Cisco has issued fixed software starting from release RI.2026.07 across affected BroadWorks components.
Operational impact
Why teams should care
Exploitation of this vulnerability can lead to unauthorized disclosure of sensitive configuration and system files, compromising confidentiality. Attackers gain access privileges equivalent to the Cisco BroadWorks user, which may enable further attacks or data breaches. As there are no workarounds, organizations need to apply updates promptly to maintain system security and protect sensitive information.
Immediate action
Cisco strongly recommends upgrading to the fixed software releases starting from RI.2026.07 for all impacted BroadWorks components to remediate this vulnerability fully. Customers should obtain upgrades through Cisco authorized channels and confirm compatibility with their hardware and software environment before upgrading.
Affected and fixed releases
Temporary risk reduction
Cisco does not provide any workarounds for this vulnerability. The only effective mitigation is to upgrade to the fixed software versions as released.
Evidence and validation checklist
- Cisco Security Advisory published August 19, 2026
- Description of improper XML external entity parsing in BroadWorks OCI XML Parser
- Exploit involves sending crafted XML messages to OCI-P service
- Successful exploitation grants filesystem read access with BroadWorks user privileges
- No available workarounds noted
- Fixed software releases starting from RI.2026.07 available
- No known public exploitation or announcements
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
