CVE-2026-20220 | Cisco Crosswork Network Change Automation up to 7.2.0 Web-based Management Interface injection (cisco-sa-cnc-inj-QNMeEmxk / EUVD-2026-37750)
A vulnerability, which was classified as critical, was found in Cisco Crosswork Network Change Automation. This affects an unknown part of the component Web-based Management Interface. The manipulation results in injection.
This vulnerability is identified as CVE-2026-20220. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.