Junglewise Threat Intelligence

CVE-2026-20030: Cisco Crosswork SQL injection in multiple products

CVE-2026-20030 · Severity: critical · CVSS 10 · Published 2026-08-19

Technologies: Cisco Crosswork Data Gateway, Cisco Crosswork Planning, Cisco Crosswork Network Controller, Cisco Crosswork Workflow Manager. Vendors: Cisco.

Executive brief

Cisco Crosswork is a suite of network management and orchestration platforms used by telecommunications operators. Multiple critical vulnerabilities in these products allow unauthenticated remote attackers to execute arbitrary SQL commands, bypass authentication, manipulate files, and steal credentials. These vulnerabilities could result in complete compromise of the platform, unauthorized access to network data, and service outages affecting operational networks.

Technical details

CVE-2026-20030 addresses improper neutralization of special characters in SQL commands (CWE-89) across the Cisco Crosswork product suite, allowing SQL injection attacks. The advisory also covers related critical vulnerabilities including missing authentication for critical functions (CWE-306), external file system control (CWE-73), and insufficient credential protection (CWE-522). These vulnerabilities were discovered during internal security review using both traditional testing processes and AI-assisted analysis. The vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Crosswork Workflow Manager in versions 7.2.1 and earlier (2.1.1 for Workflow Manager). All vulnerabilities are remotely exploitable with no authentication required and carry CVSS scores of 9.9–10.0. Patches are available in version 7.2.1-SP and 2.1.1-SP; no workarounds exist.

Affected products

  • Cisco Crosswork Data Gateway 7.2.1 and earlier
  • Cisco Crosswork Network Controller 7.2.1 and earlier
  • Cisco Crosswork Planning 7.2.1 and earlier
  • Cisco Crosswork Workflow Manager 2.1.1 and earlier

Timeline

  • 2026-08-19: disclosed: Initial public release of advisory
  • 2026-08-21: advisory: Advisory updated to include Crosswork Workflow Manager
  • 2026-08-19: patched: Fixed versions available: 7.2.1-SP (Data Gateway, Network Controller, Planning) and 2.1.1-SP (Workflow Manager)

References

Related threats