CVE-2026-20030 CVE-2026-20357 CVE-2026-20358 CVE-2026-20359
Cisco Crosswork Planning hardening release fixes SQL injection, missing authentication and more (CVE-2026-20030, CVE-2026-20357)
Cisco's August 2026 hardening release for Crosswork Planning fixes four critical, network-reachable flaws including SQL injection and missing authentication. No workarounds; Cisco reports no malicious use. Apply the hardening release.
What happened
This advisory bundles four vulnerabilities from Cisco's internal security review of Cisco Crosswork Planning. Three are reachable over the network without credentials and without user interaction: CVE-2026-20030 is an SQL injection issue (CWE-89), CVE-2026-20357 is missing authentication for a critical function (CWE-306), and CVE-2026-20358 is external control of the file system (CWE-73). The fourth, CVE-2026-20359, relates to insufficiently protected credentials (CWE-522) and requires a low-privileged account. Cisco rates CVE-2026-20030, CVE-2026-20357 and CVE-2026-20358 at CVSS 3.1 score 10, and CVE-2026-20359 at 9.9.
Depending on the specific weakness, an attacker who can reach a vulnerable instance over the network could read or modify data, alter the file system or disrupt service. The CVSS vectors show a network attack vector, low attack complexity, no user interaction and changed scope; for CVE-2026-20358 the vector indicates no confidentiality impact. Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory, and they were not publicly disclosed.
Who is affected
Only Cisco Crosswork Planning is named in this advisory. Affected versions: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.1.0, 7.1.1 and 7.2.0. If your instance runs any of these versions, it is in scope for the Cisco Crosswork Security Hardening Release: August 2026. The record on this page does not list a separate set of fixed version numbers; the remediation is the named release.
What to do now
- Obtain and apply the Cisco Crosswork Security Hardening Release: August 2026. The record here does not list a separate fixed version number, so confirm the exact release for your deployment in Cisco's advisory.
- Cisco states there are no workarounds that address these vulnerabilities. Until the release is applied, restrict network access to Cisco Crosswork Planning instances so they are reachable only from trusted management networks.
- Check all Cisco Crosswork Planning deployments against the affected versions above, and confirm after patching that the release has been applied.
Beyond the patch
Beyond this release, network-reachable authentication and injection flaws in the tools that run the network should be found before a vendor hardening release is the only control. Virtual CISO Services (vCISO) can map externally reachable services in your estate, and Implementation & Assessment Services runs the penetration tests and hardening reviews that surface SQL injection and missing-authentication issues of this kind.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-20030 Cisco Crosswork Planning | 7.0.2 7.1.0 7.0.0 7.0.4 7.0.1 7.0.3 7.2.0 7.1.1 | No fixed version listed yet |
| CVE-2026-20357 Cisco Crosswork Planning | 7.0.2 7.1.0 7.0.0 7.0.4 7.0.1 7.0.3 7.2.0 7.1.1 | No fixed version listed yet |
| CVE-2026-20358 Cisco Crosswork Planning | 7.0.2 7.1.0 7.0.0 7.0.4 7.0.1 7.0.3 7.2.0 7.1.1 | No fixed version listed yet |
| CVE-2026-20359 Cisco Crosswork Planning | 7.0.2 7.1.0 7.0.0 7.0.4 7.0.1 7.0.3 7.2.0 7.1.1 | No fixed version listed yet |