Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Ver en NVD

Análisis

Cisco Secure Workload (formerly Tetration) contains a critical vulnerability in its internal REST APIs. An unauthenticated remote attacker can gain Site Admin privileges, allowing them to read sensitive data and modify configurations across multiple tenants without any credentials.

Roles relevantes

CyberSecurityCloudKubernetesDockerBackend

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-306

EPSS

Probabilidad de explotación (próx. 30 días): 0.0005 (0.1%)
Percentil: 16.8%
EPSS: 2026-05-25

Descripción técnica

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Publicada: 20/5/2026, 17:16:20
Última modificación: 20/5/2026, 17:30:40

Referencias

InicioEventosBlogRecursosEquipo