CVE-2026-20357: Missing Authentication for Critical Function in Cisco Cisco Crosswork Planning
CVE-2026-20357 is a critical vulnerability in Cisco Crosswork Planning involving missing authentication for critical functions. This flaw allows unauthenticated remote attackers to potentially execute actions with high impact on confidentiality, integrity, and availability. The vulnerability affects multiple specific versions of Cisco Crosswork Planning. Cisco has acknowledged the issue as part of an internal security review and released a software hardening update addressing multiple vulnerabilities including this one.
AI Analysis
Technical Summary
CVE-2026-20357 describes missing authentication for critical functions in Cisco Crosswork Planning, categorized under CWE-306. This vulnerability permits unauthenticated remote attackers to perform unauthorized actions, leading to complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score is 10.0, reflecting network attack vector, no privileges required, no user interaction, and scope change. The affected versions explicitly include 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0, 7.1.1, 7.1.2, and 7.2.0. Cisco identified this vulnerability during an internal security review and issued a software hardening release to address it and other issues.
Potential Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to invoke critical functions without authentication, resulting in full compromise of confidentiality, integrity, and availability of the affected system. This can lead to unauthorized data access, modification, and disruption of service.
Mitigation Recommendations
Cisco has released a software hardening update that addresses this vulnerability as part of a broader security review. Users should apply the official Cisco updates corresponding to their affected versions to remediate this issue. Since this is not a cloud service, remediation depends on applying these patches. Patch status is confirmed by Cisco's advisory of a hardening release.
CVE-2026-20357: Missing Authentication for Critical Function in Cisco Cisco Crosswork Planning
Description
CVE-2026-20357 is a critical vulnerability in Cisco Crosswork Planning involving missing authentication for critical functions. This flaw allows unauthenticated remote attackers to potentially execute actions with high impact on confidentiality, integrity, and availability. The vulnerability affects multiple specific versions of Cisco Crosswork Planning. Cisco has acknowledged the issue as part of an internal security review and released a software hardening update addressing multiple vulnerabilities including this one.
CVSS v3.1
Score 10.0critical
Affected software
Cisco
Cisco Crosswork Planning
pkg:github/cisco/crosswork-planningRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-20357 describes missing authentication for critical functions in Cisco Crosswork Planning, categorized under CWE-306. This vulnerability permits unauthenticated remote attackers to perform unauthorized actions, leading to complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score is 10.0, reflecting network attack vector, no privileges required, no user interaction, and scope change. The affected versions explicitly include 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0, 7.1.1, 7.1.2, and 7.2.0. Cisco identified this vulnerability during an internal security review and issued a software hardening release to address it and other issues.
Potential Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to invoke critical functions without authentication, resulting in full compromise of confidentiality, integrity, and availability of the affected system. This can lead to unauthorized data access, modification, and disruption of service.
Mitigation Recommendations
Cisco has released a software hardening update that addresses this vulnerability as part of a broader security review. Users should apply the official Cisco updates corresponding to their affected versions to remediate this issue. Since this is not a cloud service, remediation depends on applying these patches. Patch status is confirmed by Cisco's advisory of a hardening release.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2025-10-08T11:59:15.414Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a85d860acd9273b49511ca5
Added to database: 08/19/2026, 16:22:56 UTC
Last enriched: 09/11/2026, 07:47:01 UTC
Last updated: 10/02/2026, 18:20:02 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.