← All Advisories

Cisco Crosswork Multiple Internally Discovered SQL Injection Vulnerabilities Allow Authenticated Attackers to Execute Arbitrary SQL Against the Underlying Database, Scoring CVSS 10.0

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-20030

Key Details

CVECVE-2026-20030
CVSS Score / Version10.0 (Critical) / CVSS v3.1
Updated2026-08-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

What to Know

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20030
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20030