Executive brief
Cisco Secure Workload, a security monitoring and compliance platform, contains multiple critical authentication and access control vulnerabilities discovered during internal security review. An attacker with network access could bypass authentication or gain unauthorized access to sensitive security data and system controls without credentials, potentially compromising the entire security posture of an organization's infrastructure.
Technical details
Cisco Secure Workload contains multiple vulnerabilities grouped under CWE-287 (improper authentication) and related CWE-284 (improper access control). The vulnerabilities allow remote attackers without authentication (no PR, no UI required) to achieve complete compromise across the system confidentiality, integrity, and availability via network attack. Root cause involves authentication bypass, missing authentication checks, or reliance on untrusted inputs. The advisory covers multiple weakness classes (CWE-119, CWE-20, CWE-284, CWE-287, CWE-74) affecting both SaaS and on-premises deployments. Patches are available: upgrade to Secure Workload 3.10.9.1 or 4.0.4.16 and update Cluster, Agent, and Connector software. No workarounds are available.
Affected products
- Cisco Secure Workload 3.10 and earlier, 4.0 before 4.0.4.16
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed releases: 3.10.9.1 and 4.0.4.16