Junglewise Threat Intelligence

CVE-2026-20317: Cisco Secure Workload authentication bypass

CVE-2026-20317 · Severity: critical · CVSS 10 · Published 2026-08-19

Technologies: Cisco Secure Workload. Vendors: Cisco.

Executive brief

Cisco Secure Workload, a security monitoring and compliance platform, contains multiple critical authentication and access control vulnerabilities discovered during internal security review. An attacker with network access could bypass authentication or gain unauthorized access to sensitive security data and system controls without credentials, potentially compromising the entire security posture of an organization's infrastructure.

Technical details

Cisco Secure Workload contains multiple vulnerabilities grouped under CWE-287 (improper authentication) and related CWE-284 (improper access control). The vulnerabilities allow remote attackers without authentication (no PR, no UI required) to achieve complete compromise across the system confidentiality, integrity, and availability via network attack. Root cause involves authentication bypass, missing authentication checks, or reliance on untrusted inputs. The advisory covers multiple weakness classes (CWE-119, CWE-20, CWE-284, CWE-287, CWE-74) affecting both SaaS and on-premises deployments. Patches are available: upgrade to Secure Workload 3.10.9.1 or 4.0.4.16 and update Cluster, Agent, and Connector software. No workarounds are available.

Affected products

  • Cisco Secure Workload 3.10 and earlier, 4.0 before 4.0.4.16

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed releases: 3.10.9.1 and 4.0.4.16

References

Related threats