Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.
Published: 2026-08-19
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from insufficiently protected credentials, classified under CWE‑522. It enables an attacker to discover or harvest stored authentication material, thereby gaining unauthorized access to the Cisco Crosswork Planning system. Because credential access could allow further exploitation of the platform, the potential impact includes compromise of sensitive configuration data and the ability to perform privileged actions beyond the intended user scope.

Affected Systems

Cisco Crosswork Planning is the product impacted by the release. No specific version information is provided in the advisory, so the vulnerability may affect all current deployments of this product pending the application of the hardening release.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity, and while the EPSS score is not available, the absence of a KEV listing does not diminish the likelihood of exploitation. The attack vector is not specified in the advisory, but given the nature of credential storage vulnerabilities, a remote or local attacker who can access the storage mechanism could exploit it. The high severity and lack of mitigation details in the environment make the risk significant until the hardening release is applied.

Generated by OpenCVE AI on August 20, 2026 at 14:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco Crosswork Security Hardening Release: August 2026 that addresses the credential protection issues
  • Verify that credential storage settings enforce encryption at rest and that default or weak passwords have been changed
  • Configure the system to require multi‑factor authentication for all administrative access and disable any unused credential management services

Generated by OpenCVE AI on August 20, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Crosswork Planning
Vendors & Products Cisco
Cisco cisco Crosswork Planning

Wed, 19 Aug 2026 19:30:00 +0000


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.
Title Cisco Crosswork Security Hardening Release: August 2026
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Cisco Crosswork Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:57:08.476Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20359

cve-icon Vulnrichment

Updated: 2026-08-19T18:31:51.604Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:40.943

Modified: 2026-08-20T16:17:22.217

Link: CVE-2026-20359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:15:05Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials