Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

View on NVD

Analysis

Cisco Secure Workload (formerly Tetration) contains a critical vulnerability in its internal REST APIs. An unauthenticated remote attacker can gain Site Admin privileges, allowing them to read sensitive data and modify configurations across multiple tenants without any credentials.

Relevant roles

CyberSecurityCloudKubernetesDockerBackend

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.8%
EPSS: 2026-05-25

Technical description

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Published: 5/20/2026, 5:16:20 PM
Last modified: 5/20/2026, 5:30:40 PM

References

HomeEventsBlogResourcesTeam