Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE) CWE-73.
Published: 2026-08-19
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability results from allowing external input to influence file system paths in Cisco Crosswork Planning, falling under CWE-73. Based on the description, it is inferred that an attacker could manipulate file paths or submit arbitrary file system requests, potentially allowing unauthorized reading, writing, or deletion of files that should be protected, leading to data disclosure or integrity compromise.

Affected Systems

Affects Cisco Crosswork Planning products released by Cisco. No specific version numbers are disclosed in the advisory, so all installations should be evaluated until an updated version that includes the hardening release is deployed.

Risk and Exploitability

A CVSS score of 10 indicates a critical vulnerability. The advisory does not detail the attack vector, and it is inferred that remote exploitation may be possible based on the high score. No public exploits are known, and the vulnerability is not listed in CISA KEV. The EPSS score is <1%, suggesting a very low probability of exploitation, although it is not zero.

Generated by OpenCVE AI on August 20, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Cisco's Crosswork Security Hardening Release to update affected products.
  • Restrict or secure any exposed file system operations, ensuring only validated paths are accepted.
  • Continuously monitor Cisco security advisories for further patches or mitigation guidance.

Generated by OpenCVE AI on August 20, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Crosswork Planning
Vendors & Products Cisco
Cisco cisco Crosswork Planning

Wed, 19 Aug 2026 19:30:00 +0000


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE)&nbsp;CWE-73.
Title Cisco Crosswork Security Hardening Release: August 2026
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Cisco Cisco Crosswork Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-21T16:15:55.596Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20358

cve-icon Vulnrichment

Updated: 2026-08-19T18:31:51.492Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:40.823

Modified: 2026-08-21T17:16:30.570

Link: CVE-2026-20358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:45:16Z

Weaknesses
  • CWE-73

    External Control of File Name or Path