Junglewise Threat Intelligence

CVE-2026-20220: Cisco Crosswork Network Controller command injection in template engine

CVE-2026-20220 · Severity: medium · CVSS 6.3 · Published 2026-06-17

Technologies: Cisco Crosswork Network Controller. Vendors: Cisco.

Executive brief

Cisco Crosswork Network Controller is a management platform used by service providers to automate and orchestrate large-scale networks. A security flaw in its web-based management interface could allow an authorized user with specific permissions to run unauthorized commands on the system. While an attacker needs valid credentials to exploit this, a successful attack could allow them to modify or delete files in certain parts of the system, potentially disrupting network management operations.

Technical details

A server-side template injection (SSTI) vulnerability exists in the configuration template engine of the Cisco Crosswork Network Controller's web-based management interface. The issue stems from insufficient input validation of user-supplied data processed by the template engine. An authenticated, remote attacker with 'template user' write permissions can exploit this by sending crafted requests to the interface. Successful exploitation allows for arbitrary command execution on the underlying Linux operating system, though the impact is restricted to file system areas where the template user has explicit write permissions. Cisco has released software updates to address this vulnerability in versions 7.1.3 and 7.2.1.

Affected products

  • Cisco Crosswork Network Controller 7.1 and earlier, 7.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory
  • 2026-06-17: patched

References

Related threats