Input Validation Flaw in Cisco Crosswork Network Controller Management Interface
CVE-2026-20220
6.3MEDIUM
What is CVE-2026-20220?
The web-based management interface of Cisco Crosswork Network Controller has been exposed to a serious vulnerability due to inadequate input validation in its configuration template engine. An authenticated remote attacker with valid template user credentials and write permissions can exploit this flaw by sending specially crafted requests. Once successfully exploited, the attacker could execute arbitrary commands on the underlying operating system within restricted areas of the file system, posing a significant risk to system integrity and security.
Affected Version(s)
Cisco Crosswork Network Change Automation 3.0.0
Cisco Crosswork Network Change Automation 3.0.1
Cisco Crosswork Network Change Automation 1.0.0