ZeroHour

CVE-2026-20030

niche

Unauthenticated SQL Injection (CWE-89) in Cisco Crosswork

CVSS 3.1
10.0 critical
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-20030 covers multiple SQL injection issues (CWE-89, improper neutralization of special elements used in SQL commands) in Cisco Crosswork, discovered by Cisco's own engineering team during a proactive internal security review and fixed in a dedicated software hardening release. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates an unauthenticated remote attacker could trigger the flaw by sending crafted input containing SQL special elements to a network-accessible component, with no user interaction required. The critical 10.0 score with scope changed (S:C) and high confidentiality, integrity, and availability impacts means a successful exploit could fully compromise the vulnerable component and potentially the wider system, allowing the attacker to run arbitrary SQL against the backing database, read or alter data, and disrupt service. Only organizations running Cisco Crosswork are affected by this CVE; the same August 19, 2026 advisory cycle also patched other Crosswork and Secure Workload flaws, five of which also scored CVSS 10.0. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days (44th percentile).

What to do: Consult the Cisco PSIRT advisory published August 19, 2026 for your specific Crosswork product and release, and apply the hardening release it specifies. Because the vector requires no privileges or user interaction, prioritize instances reachable from untrusted or user-facing networks and restrict access to Crosswork management interfaces until patched. Track Cisco's advisory for the definitive affected-version ranges and any component-level scoping within the Crosswork suite.

Affected
Cisco Crosswork
Estimated exposure
nichelikely hundreds to a few thousand deployments worldwide (estimate; no public install counts provided) — Cisco Crosswork is a specialized network automation/orchestration platform sold primarily to large service providers and enterprises rather than a mass-market product, so the installed base is small, and no version or install data was…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Six Maximum

Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.

Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.