[CIVN-2026-0326] Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability

By Published On: June 23, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: MEDIUM


Systems Affected


Cisco Crosswork Network Controller

Overview


A vulnerability has been reported in web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.


Target Audience: 

All IT administrators and individuals responsible for maintaining and updating in Software.


Risk Assessment:

High risk of data manipulation and service disruption.


Impact Assessment:

Potential impact on confidentiality, integrity, and availability of the system.


Description


This vulnerability exists due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device.


Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system.


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk


CVE Name

CVE-2026-20220




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo6l+EACgkQ3jCgcSdc

ys/ebA/+JhY5PpQwgHeSaaq1TFIf8EzVQPyZIbWdTA2TfYhCrPL3+zchiEv8QTNm

TTdavRFEN8MPIJPggYTPzHhbTFiVmT4WSQZW34jxUENvia7SkfUty48C5VvdFPSk

ytPXZ2d3IXLya2mvCGKxvi9MnBpSLWLcphusiBMssqpPLKW9kcs83zdWuDvhaZ47

nqaIfU/oIVQVMty2AeaddCPl/9atKVL0rOXiiMHYEXmicZGhGSgE4zw7BWlIMvAN

KQnU5WPRNipdkQLOvQKlZ/rRnBjxBoHO3ZFPIwvw/5CxqFJRehvg7s3v5eGx1H1k

nbik7mEOnrNL3G863lfXnI2JYchkcL/5vyZpD+OnpTmOT4ls4SvgrrKpNpzA+Liz

m62nEIeIQjyywcZhyC17vaP93M3tK5L/kim/5RUmtW6DtHPYtpD+YnPMKkG+QzhW

LCxW57nENmoQEmWfQNsaGaAzR/+jWEaVeztRZoKA3AXxU44poG97idLZ2vKtVhnB

SFPfD2m14ijHQ4YPaYfjji/s2irzZszOJiMaAxaXzCEtSrDxUykLsHaq3/t5SRxb

b4rFKgmo28tlqlIN4IhiiktG1KX1Fu/zbevBGSrcakx/7cYPPoH2i5KU6bUTRvXS

MqqQaqnAU6rUN58hQZZZiP7OoIkj2FuRwLoOSjKW0cRcconBFB8=

=zB9O

—–END PGP SIGNATURE—–

Share this article