CVE-2026-20223

CRITICAL

Cisco Secure Workload Unauthorized API Access Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-20223. PoCs published by HORKimhab.

AI-analyzed exploit summary The repository contains only a README with legal disclaimers and a LICENSE file, with no actual exploit code or technical details about CVE-2026-20223.

Description

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Exploits (1)

github STUB
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-20223

The repository contains only a README with legal disclaimers and a LICENSE file, with no actual exploit code or technical details about CVE-2026-20223.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed May 22, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0006
EPSS Percentile 19.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (50)
Cisco/Cisco Secure Workload 1.102.21
Cisco/Cisco Secure Workload 1.103.1.12
Cisco/Cisco Secure Workload 2.0.1.34
Cisco/Cisco Secure Workload 2.0.2.20
Cisco/Cisco Secure Workload 2.1.1.29
Cisco/Cisco Secure Workload 2.1.1.31
Cisco/Cisco Secure Workload 2.1.1.33
Cisco/Cisco Secure Workload 2.2.1.34
Cisco/Cisco Secure Workload 2.2.1.35
Cisco/Cisco Secure Workload 2.2.1.39
... and 40 more
Published May 20, 2026
Tracked Since May 20, 2026