
[CIVN-2026-0429] Multiple vulnerabilities in Cisco Crosswork
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Cisco Crosswork
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Cisco Crosswork Data Gateway version 7.2.1 and earlier
Cisco Crosswork Network Controller version 7.2.1 and earlier
Cisco Crosswork Planning version 7.2.1 and earlier
Cisco Crosswork Workflow Manager version 2.1.1 and earlier
Overview
Multiple vulnerabilities have been reported in Cisco Crosswork products that could allow a remote attacker to execute unauthorized SQL queries, bypass authentication, manipulate file paths, or access inadequately protected credentials on an affected system.
Target Audience:
IT administrators and individuals responsible for maintaining and updating Cisco Crosswork products.
Risk Assessment:
Critical risk of unauthorized access, information disclosure or modification, compromise of system resources, and disruption of affected network management services.
Impact Assessment:
Potential for unauthorized access, sensitive information disclosure or modification, file manipulation, credential compromise, and disruption of affected systems and services.
Description
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning and Crosswork Workflow Manager are components of Ciscos Crosswork network automation and management portfolio.
These vulnerabilities exist due to improper neutralization of SQL commands, missing authentication for critical functions, inadequate validation of file names or paths, and insufficient protection of credentials in the affected products. An attacker could exploit these vulnerabilities by sending specially crafted requests or accessing affected functions and resources, depending on the specific vulnerability.
Successful exploitation could allow an attacker to execute unauthorized database operations, bypass authentication, manipulate files or paths, access sensitive credentials, and compromise affected Cisco Crosswork systems.
Solution
Apply appropriate updates as mentioned in the Cisco Advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh
References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh
CVE Name
CVE-2026-20030
CVE-2026-20357
CVE-2026-20358
CVE-2026-20359
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqW4W0ACgkQ3jCgcSdc
ys9UBA//dPS+J83IoVs797bHmq0ZKvHlyRvXePc7RoaZ94Z8I35HIDBsqUChQ43c
P+8NJhgXA8yteHpa950K86OM99Nq0sZr0e00Cxhd+sQbU1u9ypVBSpXkBWJRm6K4
rprYoTzBR1rtoGvV0YWHicRptxNAJ/3ZFltVX8T7SPIRP0/lFE/OdrcOnWmbKwTg
cSl9010HugbTVDTPjFNS8rVrZheemk+8oh5L17RsZcawmCUMPj92Xe0xsSUQ6db3
4CDZEfVkOM2lW+l841twdVTbp7JyX2Xo35XsUnpwHB5AwFKmHQiAOpBYS5Ras82q
zSScpIfnUMKAEtgJ+JVnGpiC03DKb8lk3M8aO5bTfkJBGYDJj8G0XtWSNyunISYJ
9xcewec11obzbBP7MOoJwaOULXSj9WxbD0SsAMDI4hnMsb4yhuoJqP/8rgLdK6wi
QD4T6ucA2x2+xd/R/XwmuZQ9ofe1GzBEBcHx/GsnQSbi4YMI0iSpCMctpI7dlbw2
LfxsVBGOWvpK99eQaMNw30tB66JoEt57t1MVNKHXB6pP6HoOnvoVobTkpsdk32UV
tGRLmuJJTOe9vDL8RXf1XxirdlbXM5mLDg+NNbsnPECzD1sgB/txexJVtWktBaR/
Ho8csnNDts1AUF3lYMMmzAHy0Tb7dDI1Nj1BrYNrk3+0wqbC43M=
=aLlq
—–END PGP SIGNATURE—–


