Insufficiently Protected Credentials in Cisco Crosswork Products
CVE-2026-20359

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20359?

The vulnerability in Cisco Crosswork products arises from insufficiently protected credentials. This weakness, classified under CWE-522, poses a risk to sensitive information. Cisco's internal security review led to a software hardening release aimed at tackling multiple vulnerabilities, reinforcing the importance of credential security in safeguarding system integrity and user data.

Affected Version(s)

Cisco Crosswork Planning 7.0.2

Cisco Crosswork Planning 7.1.0

Cisco Crosswork Planning 7.0.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.