Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-20357

CVE-2026-20357: Cisco Crosswork Auth Bypass Vulnerability

CVE-2026-20357 is an authentication bypass flaw in Cisco Crosswork caused by missing authentication for critical functions. This vulnerability allows unauthorized access to sensitive operations. Learn about technical details, affected versions, impact, and mitigation strategies.

Updated:

CVE-2026-20357 Overview

CVE-2026-20357 is a missing authentication for critical function vulnerability [CWE-306] disclosed by Cisco as part of a hardening release for Cisco Crosswork. The issue was identified during an internal security review conducted by the Cisco Crosswork engineering team. The vulnerability carries a CVSS 3.1 base score of 10.0 with a scope-changed impact, indicating an unauthenticated network-based attacker can compromise confidentiality, integrity, and availability beyond the vulnerable component.

Critical Impact

An unauthenticated remote attacker can invoke critical functions in Cisco Crosswork without providing credentials, enabling full compromise of affected systems and downstream resources.

Affected Products

  • Cisco Crosswork (see the Cisco Security Advisory for specific fixed releases)
  • Deployments prior to the hardening release addressing internally discovered vulnerabilities
  • Environments with network reachability to Crosswork management interfaces

Discovery Timeline

  • 2026-08-19 - CVE-2026-20357 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-20357

Vulnerability Analysis

The vulnerability is classified under [CWE-306] Missing Authentication for Critical Function. Cisco Crosswork exposes functionality that should require authentication but performs no identity or session verification prior to executing sensitive operations. An attacker who can reach the affected network service can invoke these functions directly, bypassing the intended access control model.

The scope-changed rating in the CVSS vector indicates the impact extends beyond the vulnerable component itself. Because Crosswork orchestrates network automation, assurance, and change workflows, unauthenticated access to protected functions can propagate to managed network devices and adjacent systems. Cisco addressed CVE-2026-20357 through a broader software hardening release rather than a single point fix.

Root Cause

The root cause is the absence of authentication checks on one or more critical Crosswork functions. Rather than validating a session token, API key, or user identity before performing privileged actions, the affected code path proceeds directly to execution. This design flaw was surfaced during an internal Cisco security review of the Crosswork codebase.

Attack Vector

The attack vector is network based and requires no privileges or user interaction. An attacker sends crafted requests to the exposed Crosswork service endpoint and receives the same execution privileges as an authenticated administrator would receive on that function. See the Cisco Security Advisory for endpoint specifics.

No public proof-of-concept has been published, and no verified exploitation code is available. The vulnerability mechanism is described in prose only; refer to the vendor advisory for protocol-level detail.

Detection Methods for CVE-2026-20357

Indicators of Compromise

  • Unauthenticated HTTP or API requests to Crosswork management endpoints originating from unexpected source addresses
  • Administrative actions in Crosswork audit logs that lack a corresponding authenticated session or user identifier
  • Configuration changes on managed network devices initiated by Crosswork without a matching operator workflow

Detection Strategies

  • Inspect Crosswork application and web server logs for requests to sensitive endpoints that succeed without an authentication header or session cookie
  • Correlate Crosswork API invocations with identity provider authentication events to identify actions with no associated login
  • Baseline normal Crosswork API callers and alert on new source IPs, user agents, or geographies

Monitoring Recommendations

  • Enable verbose audit logging on Crosswork and forward events to a centralized SIEM for retention and correlation
  • Monitor north-south traffic to Crosswork management interfaces and alert on access from outside approved administrative subnets
  • Track configuration drift on devices managed by Crosswork to catch unauthorized changes originating from the platform

How to Mitigate CVE-2026-20357

Immediate Actions Required

  • Upgrade Cisco Crosswork to the fixed release identified in the Cisco Security Advisory
  • Restrict network access to Crosswork management interfaces to a dedicated administrative network or jump hosts
  • Rotate credentials, API tokens, and device secrets that Crosswork stores or uses to reach managed infrastructure
  • Review audit logs since the last known-good state for signs of unauthenticated invocation of Crosswork functions

Patch Information

Cisco released a Crosswork software hardening update that remediates CVE-2026-20357 along with additional internally discovered issues. The consolidated fix is documented in the Cisco Security Advisory. Apply the fixed release across all Crosswork nodes in the deployment.

Workarounds

  • Place Crosswork behind a network access control list that permits only approved administrator source addresses
  • Terminate exposure of Crosswork services to untrusted networks, including the internet and general enterprise VLANs
  • Require jump-host access with multi-factor authentication for any operator connecting to Crosswork management endpoints

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.