Executive brief
Cisco Crosswork is a network operations platform used for managing and orchestrating telecommunications infrastructure. CVE-2026-20358 represents a critical vulnerability allowing external attackers to manipulate the file system without authentication, potentially leading to complete system compromise, data theft, and service disruption. The vulnerability was discovered during Cisco's internal security review and is not currently being exploited in the wild.
Technical details
CVE-2026-20358 is grouped under CWE-73 (External Control of File System Pathname), allowing attackers to manipulate file system operations. The vulnerability is remotely exploitable with no authentication required and low attack complexity (CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The issue affects Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Crosswork Workflow Manager versions 7.2.1 and earlier (Workflow Manager 2.1.1 and earlier). Cisco has released patches available in versions 7.2.1-SP and 2.1.1-SP; no workarounds exist.
Affected products
- Cisco Crosswork Data Gateway 7.2.1 and earlier
- Cisco Crosswork Network Controller 7.2.1 and earlier
- Cisco Crosswork Planning 7.2.1 and earlier
- Cisco Crosswork Workflow Manager 2.1.1 and earlier
Timeline
- 2026-08-19: disclosed: Cisco published the security advisory for the hardening release
- 2026-08-19: patched: Fixed releases available: 7.2.1-SP (Data Gateway, Network Controller, Planning) and 2.1.1-SP (Workflow Manager)