Max severity Cisco Secure Workload flaw gives Site Admin privileges
Upgrade Secure Workload to release 3.10.8.3 or 4.0.3.17 and confirm API authentication is enforced.
Upgrade Secure Workload to the fixed releases 3.10.8.3 or 4.0.3.17 and confirm API authentication is enforced.
Summary
Cisco released security updates for a maximum‑severity vulnerability (CVE‑2026‑20223) in Secure Workload that allows unauthenticated attackers to gain Site Admin privileges via internal REST APIs. The flaw stems from insufficient validation and authentication when accessing API endpoints, enabling attackers to read sensitive data and alter configuration across tenant boundaries. Cisco has issued software updates for on‑premises customers and already patched the SaaS deployment. The fixed releases are 3.10.8.3 for the 3.10 line and 4.0.3.17 for the 4.0 line; customers are urged to migrate to these releases. Cisco also noted that another authentication bypass (CVE‑2026‑20182) was being actively exploited as a zero‑day, and CISA had ordered federal agencies to patch by May 17. No workarounds exist for the CVE‑2026‑20223 flaw.
Key changes
- CVE‑2026‑20223: unauthenticated REST API flaw grants Site Admin privileges
- No workarounds; patch required for on‑premises and SaaS
- Fixed releases: 3.10.8.3 and 4.0.3.17
- Cisco released updates for on‑premises customers and patched SaaS deployment
- CISA added CVE‑2026‑20182 to KEV and ordered agencies patch by May 17
- Vulnerability allows reading sensitive data and changing configuration across tenant boundaries