Cisco Secure Workload Unauthorized API Access Vulnerability
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy Security Impact Rating: Critical CVE: CVE-2026-20223
CSIRTS triage
- What
- There is an unauthorized API access vulnerability in Cisco Secure Workload.
- Who is affected
- Users of Cisco Secure Workload are affected.
- Urgency
- Immediate remediation is critical due to the potential for unauthorized access and data exposure.
- Action
- Update to the latest version of Cisco Secure Workload.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Cisco Secure Workload
Get an email when a new Cisco Secure Workload advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-202230.83% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20223 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Cisco Secure Workload
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workloadncsc-nl · 2026-08-21
- high[NEW] [high] Cisco Secure Workload: Multiple vulnerabilitiescert-bund · 2026-08-20
- highCVE-2026-20319: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Sec…nvd · 2026-08-19
- criticalCVE-2026-20318: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Sec…nvd · 2026-08-19
- criticalCVE-2026-20317: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Sec…nvd · 2026-08-19
- criticalCVE-2026-20315: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Sec…nvd · 2026-08-19
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19