Junglewise Threat Intelligence

CVE-2026-20223: Cisco Secure Workload auth bypass in internal REST APIs

CVE-2026-20223 · Severity: critical · CVSS 10 · Published 2026-05-20

Vendors: Cisco.

Executive brief

Cisco Secure Workload, a platform used for data center visibility and microsegmentation, contains a critical security flaw in its internal programming interfaces. An unauthorized attacker could remotely gain full administrative control over the system without needing a password. This allows the attacker to view sensitive data and change security configurations across different customer environments, potentially leading to a total compromise of the managed network.

Technical details

A vulnerability in Cisco Secure Workload (formerly Tetration) stems from missing authentication (CWE-306) and insufficient validation within internal REST API endpoints. A remote, unauthenticated attacker can exploit this by sending crafted API requests to these internal endpoints. Successful exploitation grants the attacker Site Admin privileges, enabling them to bypass tenant boundaries, read sensitive information, and modify system configurations. The vulnerability affects both SaaS and on-prem deployments but does not impact the web-based management interface. Cisco has released updates to address this issue in versions 3.10.8.3 and 4.0.3.17.

Affected products

  • Cisco Secure Workload Cluster Software 3.9 and earlier, 3.10 prior to 3.10.8.3, 4.0 prior to 4.0.3.17

Timeline

  • 2026-05-20: disclosed: Initial public release of Cisco advisory
  • 2026-05-20: patched: Fixed versions released and SaaS environments updated

References