Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system. This vulnerability affects only areas of the operating system for which the template user has write permissions. To exploit this vulnerability, the attacker must have valid template user credentials with write permissions. Template users with read permissions cannot exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk Security Impact Rating: Medium CVE: CVE-2026-20220
CSIRTS triage
- What
- A server-side template injection vulnerability could allow an authenticated attacker to execute arbitrary commands.
- Who is affected
- Authenticated users with template user credentials on the affected Cisco Crosswork Network Controller.
- Urgency
- Remediation is urgent due to the potential for arbitrary command execution.
- Action
- Users should apply the software updates released by Cisco.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Crosswork Network Controller
Get an email when a new Crosswork Network Controller advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-202200.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20220 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Cisco Crosswork Network
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisorycisco-psirt · 2026-05-14
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19