Cisco Crosswork External File System Control Vulnerability (CWE-73)
CVE-2026-20358 Published on August 19, 2026
Cisco Crosswork Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE) CWE-73.
Vulnerability Analysis
CVE-2026-20358 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Type
External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
Affected Versions
Cisco Crosswork Planning:- Version 7.0.2 is affected.
- Version 7.1.0 is affected.
- Version 7.0.0 is affected.
- Version 7.0.4 is affected.
- Version 7.0.1 is affected.
- Version 7.0.3 is affected.
- Version 7.2.0 is affected.
- Version 7.1.1 is affected.
- Version 7.1.2 is affected.