216.73.217.22

CVE-2026-20223

· Published 20/05/2026 17:16 · Modified 20/05/2026 17:30

Labels: CVE-2026-20223 2026-05-20CVE-2026-20223CWE-306[email protected]

Essential information

Published
20/05/2026 17:16
Modified
20/05/2026 17:30
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cisco / secure workload cpe:2.3:a:cisco:secure_workload:*:*:*:*:*:*:*:*

References