File System Vulnerabilities in Cisco Crosswork
CVE-2026-20358

10CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20358?

An internal security review by Cisco's Crosswork engineering team has led to the identification of vulnerabilities related to external control of the file system. These issues, documented under CWE-73, could allow unauthorized manipulation of the file system, posing potential security risks. Cisco has released a software hardening update aimed at mitigating these vulnerabilities, enhancing the overall security posture of the Crosswork product.

Affected Version(s)

Cisco Crosswork Planning 7.0.2

Cisco Crosswork Planning 7.1.0

Cisco Crosswork Planning 7.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.