Sceawere

Vulnerability Detail

CVE-2026-20358UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cisco Crosswork CWE-73 Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
2h ago
Vendor
Cisco
Product
Cisco Crosswork Planning
Attack Type
External Control of File Name or Path
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE) CWE-73.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-19T17:18:40.823Z",
  "pubdate": "2026-08-19T17:18:40.823Z",
  "executiveSummary": "An internal security review conducted by the Cisco Crosswork engineering team identified multiple internally discovered vulnerabilities tracked under CVE-2026-20358.\nThe identified security issues are classified under Common Weakness Enumeration CWE-73, which pertains to the external control of file system paths or names.\nThe affected product is Cisco Crosswork.\nThese vulnerabilities arise from improper input validation where external user-controlled data dictates file system operations, potentially allowing attackers to manipulate file paths.\nSuccessful exploitation of these weaknesses can lead to unauthorized file system access, potentially compromising the integrity and confidentiality of the underlying host system or application data.\nThe software hardening release addresses these internally discovered vulnerabilities to restore proper validation and secure file handling within the application architecture.\nRisk implications include unauthorized read or write operations depending on the specific attack vector and context of the affected file handling routines within Cisco Crosswork.\nAttacker capabilities and specific exploitation requirements are constrained by the privileges associated with the vulnerable component and the input vectors exposed by the application.",
  "technicalDetails": "The vulnerabilities tracked by CVE-2026-20358 stem from CWE-73, designated as External Control of File Name or Path.\nThe root cause involves the application accepting untrusted input from external sources without sufficient sanitization, canonicalization, or validation, and subsequently utilizing that input directly in file system APIs or file I/O operations.\nThe vulnerable component resides within the Cisco Crosswork codebase where file paths are dynamically constructed or resolved based on unverified parameters.\nDuring a typical attack flow, an adversary supplies a maliciously crafted input containing path traversal sequences or absolute file paths through an exposed application interface.\nWhen the vulnerable component processes this input without adequate boundary checks, the execution context resolves the path to unintended locations within the underlying file system.\nDepending on the exact implementation flaws and access controls enforced by the operating system, this permits unauthorized reading, writing, or overwriting of critical system files, configuration data, or application binaries.\nThe technical impact directly correlates to the permissions of the process executing the vulnerable file operations, potentially leading to arbitrary file access or state corruption within Cisco Crosswork.\nAuthentication requirements, privilege requirements, network exposure, and precise payload behaviors are dictated by the specific attack surfaces exposed by the affected modules within Cisco Crosswork as discovered during the internal engineering review."
}
CVE-2026-20358: Cisco Crosswork CWE-73 Vulnerability (CRITICAL Severity, CVSS: 10.0) - Sceawere