CVE-2026-20359 – Cisco Crosswork Planning
“Critical weaknesses in authentication, data handling, and credential protection can expose core Crosswork Planning security boundaries.”
Cisco Crosswork Planning is affected by four Critical vulnerabilities addressed through a software hardening release. CVE-2026-20030 has a CVSS score of 10.0, Critical severity and involves SQL command injection. CVE-2026-20357 has a CVSS score of 10.0, Critical severity and involves missing authentication for critical functionality. CVE-2026-20358 also has a CVSS score of 10.0, Critical severity and involves external control of filesystem paths.
CVE-2026-20359 has a CVSS score of 9.9, Critical severity and involves insufficient protection of credentials. Cisco identified these vulnerabilities through an internal security review and addressed them as part of its Crosswork Planning software hardening effort.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-522