External Control of File Name or Path in Cisco Systems, Inc products - CVE-2026-20358
Published: August 19, 2026
Vulnerability identifier: #VU144388
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20358
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to external control of file system in file system handling functionality when processing crafted input. A remote attacker can supply crafted file system input to execute arbitrary code.
Affected software
Crosswork Data Gateway
Crosswork Network Controller
Crosswork Planning
Crosswork Network Controller
Crosswork Planning
How to mitigate CVE-2026-20358
Install security update from vendor's website.
Crosswork Data Gateway - update to 7.2.1-SP
Crosswork Network Controller - update to 7.2.1-SP
Crosswork Planning - update to 7.2.1-SP
Crosswork Network Controller - update to 7.2.1-SP
Crosswork Planning - update to 7.2.1-SP