- Description
- A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- secure_workload
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 5.8
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
- psirt@cisco.com
- CWE-306
- Hype score
- Not currently trending
Cisco Secure Workload の脆弱性 CVE-2026-20223 が FIX:Site Admin 権限奪取の恐れ https://t.co/2hdJc08EAt Cisco Secure Workload の脆弱性 CVE-2026-20223 は、内部の REST API
@iototsecnews
27 May 2026
93 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-20223 — Cisco Secure Workload CVSS 10.0 | Unauthenticated remote → Site Admin Crafted req to internal REST API = full microseg control, no creds needed. Patch immediately. #ThreatIntel #CVE #CVE202620223 #CyberSecurity
@NoctisIntel
26 May 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2026-20223 في Cisco Secure Workload، CVSS 10.0. مهاجم غير مُصادق يرسل HTTP request مُصاغ لـ internal REST API ليحصل على صلاحيات Site Admin فوراً. تؤثر على SaaS والـ on-premises. لا workarounds، الترقية
@KasperskyDev
25 May 2026
106 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-20223: Cisco Secure Workload Auth Bypass Grants Site Admin Access https://t.co/FxnK7p1t9I CVE-2026-20223: Cisco Secure Workload Auth Bypass Grants Site Admin Access Cisco has patched a maximum-severity vulnerability in Cisco Secure Workload (CSW) Cluster Software tra
@f1tym1
25 May 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2026-20223 في Cisco Secure Workload - CVSS 10.0 Critical. مهاجم غير مصادق يرسل طلب HTTP واحداً للـ REST API الداخلي فيحصل على صلاحيات Site Admin كاملة عبر حدود الـ tenant. Fix: 3.10.8.3 و4.0.3.17. لا
@KasperskyDev
24 May 2026
104 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2016-5195 3 - CVE-2026-20223 4 - CVE-2026-41940 5 - CVE-2026-41089 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
23 May 2026
322 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Secure Workload Unauthorized API Access Vulnerability (CVE-2026-20223) https://t.co/k2n5yDtGy7 #patchmanagement
@eyalestrin
23 May 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔨マイクロソフト、Defenderの悪用されたゼロデイを修正(CVE-2026-41091、CVE-2026-45498) ⚠️Cisco Secure WorkloadにCVSS 10.0の重大な脆弱性、サイト管理者権限を付与する恐れ(CVE-2026-20223) 〜サイバーアラート5月22日
@MachinaRecord
22 May 2026
167 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Cisco fixed maximum severity flaw CVE-2026-20223 in Secure Workload: Cisco fixed a critical Secure Workload flaw (CVE-2026-20223) that could let attackers gain Site Admin privileges through crafted API requests. Cisco released patches for a critical… https://t.co/rQMukDmttf htt
@shah_sheikh
21 May 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attention, elevated activities detected targeting Cisco Secure Workload (CVE-2026-20223) https://t.co/D9p9PIFOt2
@vuldb
21 May 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco drops an urgent advisory for CVE-2026-20223 (CVSS 10.0) in Secure Workload. Unauthenticated remote attackers can steal full Site Admin privileges. #CiscoSecurity #CVE #CVSS10 #ZeroTrust #CloudSecurity #Microsegmentation #InfoSec #CyberSecurity https://t.co/HplbZiipct http
@Daily_CyberSec
21 May 2026
207 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-20223 — CVSS 10/10 ██████████ A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/RabcQfeGrO
@OrizonCyber
20 May 2026
120 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FE262C72-F362-4A80-A879-EF1B581924C9",
"versionEndExcluding": "3.10.8.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F83C5A19-263C-4279-AE94-C572BC929E15",
"versionEndExcluding": "4.0.3.17",
"versionStartIncluding": "4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]