Junglewise Threat Intelligence

CVE-2026-20357: Cisco Crosswork missing authentication for critical functions

CVE-2026-20357 · Severity: critical · CVSS 10 · Published 2026-08-19

Technologies: Cisco Crosswork Data Gateway, Cisco Crosswork Planning, Cisco Crosswork Network Controller, Cisco Crosswork Workflow Manager. Vendors: Cisco.

Executive brief

Cisco Crosswork is a network management and orchestration platform used by service providers to manage critical infrastructure. This vulnerability allows unauthenticated attackers to perform critical functions without any credentials, potentially compromising network operations, enabling unauthorized configuration changes, and exposing sensitive network data. The vulnerability affects multiple Crosswork components (Data Gateway, Network Controller, Planning, and Workflow Manager) and requires a software patch to remediate.

Technical details

The vulnerability is a missing authentication issue (CWE-306) affecting Cisco Crosswork platforms versions 7.2.1 and earlier (and Workflow Manager 2.1.1 and earlier). It allows attackers to access critical functions over the network without providing authentication credentials, achieving high impact across confidentiality, integrity, and availability. The attack vector is network-based with no authentication required and no user interaction needed. Patches are available in Crosswork 7.2.1-SP and Workflow Manager 2.1.1-SP. These vulnerabilities were discovered during internal security testing and are not currently known to be exploited in the wild.

Affected products

  • Cisco Crosswork Data Gateway 7.2.1 and earlier
  • Cisco Crosswork Network Controller 7.2.1 and earlier
  • Cisco Crosswork Planning 7.2.1 and earlier
  • Cisco Crosswork Workflow Manager 2.1.1 and earlier

Timeline

  • 2026-08-19: disclosed: Initial public release of advisory
  • 2026-08-19: patched: Fixed releases available: 7.2.1-SP for Data Gateway, Network Controller, Planning; 2.1.1-SP for Workflow Manager
  • 2026-08-21: advisory: Advisory updated to include Workflow Manager as affected product

References

Related threats