SQL Injection Vulnerability in Cisco Crosswork Products
CVE-2026-20030

10CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2026

Badges

📈 Score: 713👾 Exploit Exists

What is CVE-2026-20030?

CVE-2026-20030 is a significant security vulnerability found in Cisco's Crosswork products, which are designed to facilitate network automation and intelligent management for service providers. This particular vulnerability stems from improper handling of SQL commands, categorized under the Common Weakness Enumeration as CWE-89, resulting in potential SQL injection threats. If successfully exploited, this flaw could lead to unauthorized access to sensitive data stored in the database, allowing attackers to manipulate or extract information crucial to network operations. As these products are integral to the functioning of telecommunications services, any compromise could severely disrupt operational integrity and data security for organizations that rely on them.

Potential impact of CVE-2026-20030

  1. Data Breach Risk: Exploiting this vulnerability could allow attackers to access sensitive information within an organization’s databases, leading to compromised data integrity and the potential for sensitive information leaks.

  2. Operational Disruption: Given that Cisco Crosswork products are used for network management, a successful SQL injection attack could disrupt network services, causing downtime and negatively affecting customer satisfaction and trust.

  3. Increased Attack Surface: The presence of this vulnerability may encourage further targeted attacks on affected systems, potentially leading to more serious exploits, including unauthorized access and lateral movement within an organization's IT infrastructure.

Affected Version(s)

Cisco Crosswork Planning 7.0.2

Cisco Crosswork Planning 7.1.0

Cisco Crosswork Planning 7.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.