Junglewise Threat Intelligence

CVE-2026-20359: Cisco Crosswork insufficiently protected credentials

CVE-2026-20359 · Severity: critical · CVSS 9.9 · Published 2026-08-19

Technologies: Cisco Crosswork Data Gateway, Cisco Crosswork Planning, Cisco Crosswork Network Controller, Cisco Crosswork Workflow Manager. Vendors: Cisco.

Executive brief

Cisco Crosswork is a network management platform used to control and optimize enterprise network operations. Multiple vulnerabilities in Crosswork's credential storage and authentication mechanisms could allow attackers to compromise network infrastructure management, leading to unauthorized access to critical network operations, data theft, and potential service disruption.

Technical details

This advisory addresses multiple hardening vulnerabilities in Cisco Crosswork, with CVE-2026-20359 specifically tracking insufficiently protected credentials (CWE-522). The vulnerabilities span multiple weakness categories including SQL injection (CWE-89), missing authentication (CWE-306), and external file system control (CWE-73), all reachable over the network without authentication required. These internally discovered vulnerabilities affect Crosswork Data Gateway, Network Controller, Planning, and Workflow Manager platforms. Patches are available in software versions 7.2.1-SP and 2.1.1-SP for the respective products; no workarounds exist.

Affected products

  • Cisco Crosswork Data Gateway 7.2.1 and earlier
  • Cisco Crosswork Network Controller 7.2.1 and earlier
  • Cisco Crosswork Planning 7.2.1 and earlier
  • Cisco Crosswork Workflow Manager 2.1.1 and earlier

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed releases available: Data Gateway/Network Controller/Planning 7.2.1-SP, Workflow Manager 2.1.1-SP

References

Related threats