Cisco Crosswork CVE202620359: Credential Storage Vulnerability (CWE522)
CVE-2026-20359 Published on August 19, 2026
Cisco Crosswork Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.
Vulnerability Analysis
CVE-2026-20359 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Affected Versions
Cisco Crosswork Planning:- Version 7.0.2 is affected.
- Version 7.1.0 is affected.
- Version 7.0.0 is affected.
- Version 7.0.4 is affected.
- Version 7.0.1 is affected.
- Version 7.0.3 is affected.
- Version 7.2.0 is affected.
- Version 7.1.1 is affected.
- Version 7.1.2 is affected.