CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0

cve · CVE-2026-20223

Coverage
1
first 2026-05-22 → last 2026-05-25
Latest activity
2026-05-22
CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all…
Peak priority
high
1 high
Targets
·
no sector or region stated
Sources cited
5
5 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-20223, newest first. Check the date before acting on an older one.

  • Restrict network access to Cisco Secure Workload REST API management plane; CVE-2026-20223 is CVSS 10.0 zero-auth; on-prem deployments require manual upgrade to 3.10.8.3 or 4.0.3.17 (3.9 and earlier: migrate). Until patched, firewall the Secure Workload cluster API endpoints to trusted management hosts only.
    2026-05-22CVE-2026-20223

Story timeline

  1. 2026-05-22CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround
    trending-vulnerabilities

Hunting pivots

ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-22/cve-2026-20223-cisco-secure-workload-cvss-10-0-zero-auth-res · ATT&CK page ↗

Entries about Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0 (1)

2026-05-22 · view entry permalink →

CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround

CVE-2026-20223 (CVSS 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) is an access validation failure in the internal REST API of Cisco Secure Workload (formerly Tetration), the enterprise micro-segmentation platform (Cisco PSIRT, 2026-05-20). An unauthenticated remote attacker sends a single crafted HTTP request to an internal API endpoint to be granted Site Admin-level privileges, enabling cross-tenant data read, configuration modification, and full visibility over workload segmentation policy across all tenant boundaries. Both SaaS-hosted and on-premises deployments are affected; Cisco silently patched SaaS. On-premises operators must upgrade: 4.0.x → 4.0.3.17; 3.10.x → 3.10.8.3; 3.9 and earlier must migrate (no fix available). No workaround exists. Cisco found no evidence of exploitation at disclosure (2026-05-20); the vulnerability was discovered internally. NCSC-CH flagged this on 2026-05-21. The attack surface is the internal REST API management plane, restrict untrusted network access to the Secure Workload cluster API as the primary compensating control until patching is complete. Technique: T1190 Exploit Public-Facing Application. This is distinct from CVE-2026-20182 (Cisco Catalyst SD-WAN) covered on 2026-05-20.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-34926 Trend Micro Apex One On-Premise 6.7 n/a Yes (2026-05-21) Yes (ITW) Build 17079 Trend Micro
CVE-2025-34291 Langflow AI Platform 9.4 (v4) / 8.8 (v3) n/a Yes (2026-05-21) Yes (ITW since Jan 2026) >= 1.7.0 / 1.9.3 CISA KEV
CVE-2026-20223 Cisco Secure Workload 10.0 n/a No No (disclosed internally) 3.10.8.3 / 4.0.3.17 Cisco PSIRT
vulnerability22 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Vulns1

Source distribution

  • cisa.gov1 (20%)
  • sec.cloudapps.cisco.com1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)
  • success.trendmicro.com1 (20%)
  • theregister.com1 (20%)