Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.
Published: 2026-08-19
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication requirement for critical internal functions in Cisco Crosswork Planning. An attacker can invoke these functions without credential verification, potentially enabling unauthorized configuration changes or exposure of sensitive data. The flaw is identified as a failure to enforce authentication before authorized actions (CWE-306).

Affected Systems

The affected product is Cisco Crosswork Planning. Any installation of this product prior to the August 2026 hardening release is vulnerable, as no specific version details are provided.

Risk and Exploitability

The CVSS score of 10 classifies the vulnerability as critical. The EPSS of less than 1% indicates a very low probability of exploitation, yet the high severity suggests that, if the vulnerable functions are exposed, the risk of impact remains significant. Because the description does not specify how the critical functions are accessed, the attack vector remains uncertain, and an attacker may need to determine whether the functions are network‑exposed or callable locally. The lack of a CISA KEV listing suggests no publicly known exploits exist at this time.

Generated by OpenCVE AI on August 20, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the August 2026 Cisco Crosswork Hardening Release that enforces authentication for the affected functions.
  • Reconfigure or disable any features that allow execution of critical functions without authentication.
  • Segregate Crosswork Planning from untrusted networks by segmenting the network or applying firewall rules until the hardening release is applied.

Generated by OpenCVE AI on August 20, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Crosswork Planning
Vendors & Products Cisco
Cisco cisco Crosswork Planning

Wed, 19 Aug 2026 19:30:00 +0000


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.
Title Cisco Crosswork Security Hardening Release: August 2026
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Cisco Crosswork Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-21T16:16:10.667Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20357

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:40.697

Modified: 2026-08-21T17:16:30.457

Link: CVE-2026-20357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:45:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function