CVE-2026-20358

10.0

Cisco · Crosswork Planning

An external control of file system path vulnerability in Cisco Crosswork Planning allows remote attackers to manipulate file operations.

Executive summary

Cisco Crosswork Planning is susceptible to unauthorized file system manipulation, which could lead to critical system impact and service disruption.

Vulnerability

This vulnerability is classified as external control of file name or path (CWE-73). It allows an unauthenticated remote attacker to influence file system operations, potentially resulting in unauthorized file modification or deletion.

Business impact

With a CVSS score of 10.0, this vulnerability presents a critical threat to system integrity and availability. An attacker could potentially overwrite configuration files or execute arbitrary code through file system manipulation, leading to a complete compromise of the application environment.

Remediation

Immediate Action: Upgrade to the latest version of Cisco Crosswork Planning as recommended by the vendor.

Proactive Monitoring: Monitor file system integrity and review logs for suspicious file access patterns or unauthorized path traversal attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to block requests containing path traversal characters or suspicious file path patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability demands immediate attention due to its potential for total system compromise. Administrators should apply the vendor-provided security patches as soon as they become available to prevent exploitation.

More Cisco CVEs