Impact
The vulnerability is a missing authentication requirement for critical internal functions in Cisco Crosswork Planning. An attacker can invoke these functions without credential verification, potentially enabling unauthorized configuration changes or exposure of sensitive data. The flaw is identified as a failure to enforce authentication before authorized actions (CWE-306).
Affected Systems
The affected product is Cisco Crosswork Planning. Any installation of this product prior to the August 2026 hardening release is vulnerable, as no specific version details are provided.
Risk and Exploitability
The CVSS score of 10 classifies the vulnerability as critical. The EPSS of less than 1% indicates a very low probability of exploitation, yet the high severity suggests that, if the vulnerable functions are exposed, the risk of impact remains significant. Because the description does not specify how the critical functions are accessed, the attack vector remains uncertain, and an attacker may need to determine whether the functions are network‑exposed or callable locally. The lack of a CISA KEV listing suggests no publicly known exploits exist at this time.
OpenCVE Enrichment