[CIVN-2026-0429] Multiple vulnerabilities in Cisco Crosswork

By Published On: September 1, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple vulnerabilities in Cisco Crosswork


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Cisco Crosswork Data Gateway version 7.2.1 and earlier

Cisco Crosswork Network Controller version 7.2.1 and earlier

Cisco Crosswork Planning version 7.2.1 and earlier

Cisco Crosswork Workflow Manager version 2.1.1 and earlier

Overview


Multiple vulnerabilities have been reported in Cisco Crosswork products that could allow a remote attacker to execute unauthorized SQL queries, bypass authentication, manipulate file paths, or access inadequately protected credentials on an affected system.


Target Audience:

IT administrators and individuals responsible for maintaining and updating Cisco Crosswork products.


Risk Assessment:

Critical risk of unauthorized access, information disclosure or modification, compromise of system resources, and disruption of affected network management services.


Impact Assessment:

Potential for unauthorized access, sensitive information disclosure or modification, file manipulation, credential compromise, and disruption of affected systems and services.


Description


Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning and Crosswork Workflow Manager are components of Ciscos Crosswork network automation and management portfolio.


These vulnerabilities exist due to improper neutralization of SQL commands, missing authentication for critical functions, inadequate validation of file names or paths, and insufficient protection of credentials in the affected products. An attacker could exploit these vulnerabilities by sending specially crafted requests or accessing affected functions and resources, depending on the specific vulnerability.


Successful exploitation could allow an attacker to execute unauthorized database operations, bypass authentication, manipulate files or paths, access sensitive credentials, and compromise affected Cisco Crosswork systems.


Solution


Apply appropriate updates as mentioned in the Cisco Advisory:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh


References


 

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh


CVE Name

CVE-2026-20030

CVE-2026-20357

CVE-2026-20358

CVE-2026-20359




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqW4W0ACgkQ3jCgcSdc

ys9UBA//dPS+J83IoVs797bHmq0ZKvHlyRvXePc7RoaZ94Z8I35HIDBsqUChQ43c

P+8NJhgXA8yteHpa950K86OM99Nq0sZr0e00Cxhd+sQbU1u9ypVBSpXkBWJRm6K4

rprYoTzBR1rtoGvV0YWHicRptxNAJ/3ZFltVX8T7SPIRP0/lFE/OdrcOnWmbKwTg

cSl9010HugbTVDTPjFNS8rVrZheemk+8oh5L17RsZcawmCUMPj92Xe0xsSUQ6db3

4CDZEfVkOM2lW+l841twdVTbp7JyX2Xo35XsUnpwHB5AwFKmHQiAOpBYS5Ras82q

zSScpIfnUMKAEtgJ+JVnGpiC03DKb8lk3M8aO5bTfkJBGYDJj8G0XtWSNyunISYJ

9xcewec11obzbBP7MOoJwaOULXSj9WxbD0SsAMDI4hnMsb4yhuoJqP/8rgLdK6wi

QD4T6ucA2x2+xd/R/XwmuZQ9ofe1GzBEBcHx/GsnQSbi4YMI0iSpCMctpI7dlbw2

LfxsVBGOWvpK99eQaMNw30tB66JoEt57t1MVNKHXB6pP6HoOnvoVobTkpsdk32UV

tGRLmuJJTOe9vDL8RXf1XxirdlbXM5mLDg+NNbsnPECzD1sgB/txexJVtWktBaR/

Ho8csnNDts1AUF3lYMMmzAHy0Tb7dDI1Nj1BrYNrk3+0wqbC43M=

=aLlq

—–END PGP SIGNATURE—–

Share this article