Executive brief
Cisco Secure Workload, a platform for monitoring and controlling workload security across data centers and cloud environments, contains multiple critical vulnerabilities including improper access control issues. An attacker with network access could bypass authentication or authorization controls, potentially gaining unauthorized administrative access to protected systems and data.
Technical details
CVE-2026-20315 represents improper access control vulnerabilities (CWE-284) identified in Cisco Secure Workload during an internal security review. The vulnerabilities impact both SaaS and on-premises deployments and do not require user interaction or authentication. An unauthenticated remote attacker can leverage these access control flaws to bypass authorization mechanisms and gain unauthorized access to the Cluster, Agent, and Connector components. Patches are available: upgrade to Secure Workload 3.10.9.1 or later for the 3.x branch, or 4.0.4.16 or later for the 4.x branch. No workarounds are available.
Affected products
- Cisco Secure Workload 3.10 and earlier, 4.0 before 4.0.4.16
Timeline
- 2026-08-19: disclosed