CVE-2026-20223
Cisco Secure Workload has a flaw that lets anyone on the network call its internal REST APIs without authentication, giving them full Site Admin powers. This means an attacker could read confidential data or change settings across tenants. The vulnerability is critical because it requires no credentials and can be exploited remotely.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
All versions of Cisco Secure Workload that expose the internal REST APIs, typically used by organizations managing workloads in a multi-tenant environment.
Real-world impact
An attacker could read sensitive information and make configuration changes across tenant boundaries with the privileges of a Site Admin user.
Why this severity
The CVSS score is 10 because the flaw allows unauthenticated remote exploitation with complete control over the system, meeting the criteria for maximum impact.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 20, 2026 · May 20, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- sec.cloudapps.cisco.com/security/center/content/Cis…vendor advisory