
[CIVN-2026-0326] Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Systems Affected
Cisco Crosswork Network Controller
Overview
A vulnerability has been reported in web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating in Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk
CVE Name
CVE-2026-20220
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo6l+EACgkQ3jCgcSdc
ys/ebA/+JhY5PpQwgHeSaaq1TFIf8EzVQPyZIbWdTA2TfYhCrPL3+zchiEv8QTNm
TTdavRFEN8MPIJPggYTPzHhbTFiVmT4WSQZW34jxUENvia7SkfUty48C5VvdFPSk
ytPXZ2d3IXLya2mvCGKxvi9MnBpSLWLcphusiBMssqpPLKW9kcs83zdWuDvhaZ47
nqaIfU/oIVQVMty2AeaddCPl/9atKVL0rOXiiMHYEXmicZGhGSgE4zw7BWlIMvAN
KQnU5WPRNipdkQLOvQKlZ/rRnBjxBoHO3ZFPIwvw/5CxqFJRehvg7s3v5eGx1H1k
nbik7mEOnrNL3G863lfXnI2JYchkcL/5vyZpD+OnpTmOT4ls4SvgrrKpNpzA+Liz
m62nEIeIQjyywcZhyC17vaP93M3tK5L/kim/5RUmtW6DtHPYtpD+YnPMKkG+QzhW
LCxW57nENmoQEmWfQNsaGaAzR/+jWEaVeztRZoKA3AXxU44poG97idLZ2vKtVhnB
SFPfD2m14ijHQ4YPaYfjji/s2irzZszOJiMaAxaXzCEtSrDxUykLsHaq3/t5SRxb
b4rFKgmo28tlqlIN4IhiiktG1KX1Fu/zbevBGSrcakx/7cYPPoH2i5KU6bUTRvXS
MqqQaqnAU6rUN58hQZZZiP7OoIkj2FuRwLoOSjKW0cRcconBFB8=
=zB9O
—–END PGP SIGNATURE—–


