{"id":"CVE-2026-20223","title":"A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role.\r\n\r\nThis vulnerability …","summary":"A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role.\r\n\r\nThis vulnerability …","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"cisco","product":"secure_workload","affected":["secure_workload < 3.10.8.3","secure_workload >= 4.0, < 4.0.3.17"],"patched":["secure_workload 4.0.3.17"],"published":"2026-05-20","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20223","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy","label":"psirt@cisco.com"}],"tags":["nvd","exploit-available"],"epss":0.00835,"epssPercentile":0.56218,"ingestedAt":"2026-07-01T09:50:45.859Z","exploits":{"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2026-20223"],"checkedAt":"2026-09-24T07:53:00.425Z"},"exploitAvailable":true,"slug":"CVE-2026-20223","body":"## Overview\n\nA vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role.\r\n\r\nThis vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the&nbsp;Site Admin user.&nbsp;\n\n## Affected\n\n- `secure_workload < 3.10.8.3`\n- `secure_workload >= 4.0, < 4.0.3.17`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `secure_workload 4.0.3.17`","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":55,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4996,"id":"CVE-2026-20223","ts":1788887225292,"field":"exploit_available","old":"false","new":"true"},{"seq":3879,"id":"CVE-2026-20223","ts":1788886357472,"field":"exploit_available","old":"true","new":"false"},{"seq":2701,"id":"CVE-2026-20223","ts":1788883022590,"field":"exploit_available","old":"false","new":"true"},{"seq":1730,"id":"CVE-2026-20223","ts":1788882427117,"field":"exploit_available","old":"true","new":"false"},{"seq":836,"id":"CVE-2026-20223","ts":1788881860133,"field":"exploit_available","old":"false","new":"true"}]}