Input Validation Flaw in Cisco Crosswork Network Controller Management Interface
CVE-2026-20220

6.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
17 June 2026

Badges

👾 Exploit Exists

What is CVE-2026-20220?

The web-based management interface of Cisco Crosswork Network Controller has been exposed to a serious vulnerability due to inadequate input validation in its configuration template engine. An authenticated remote attacker with valid template user credentials and write permissions can exploit this flaw by sending specially crafted requests. Once successfully exploited, the attacker could execute arbitrary commands on the underlying operating system within restricted areas of the file system, posing a significant risk to system integrity and security.

Affected Version(s)

Cisco Crosswork Network Change Automation 3.0.0

Cisco Crosswork Network Change Automation 3.0.1

Cisco Crosswork Network Change Automation 1.0.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.