Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access

Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access

By Abinaya
Publication Date: 2026-05-21 09:20:00

Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain unauthorized access to sensitive resources via internal APIs.

The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.0 and is categorized under CWE-306 (Missing Authentication for Critical Function).

The issue stems from improper authentication and insufficient validation in internal REST API endpoints.

An attacker can exploit this flaw by sending specially crafted API requests to affected endpoints without requiring any authentication.

Successful exploitation could grant attackers Site Admin-level privileges, enabling them to gain full control over affected environments.

Cisco Secure Workload Vulnerability

With elevated privileges, attackers may access sensitive data, modify configurations, and potentially impact multiple tenants within a shared deployment.

This cross-tenant risk significantly increases the…