[CIVN-2026-0435] Cisco Secure Workload Unauthorized API Access Vulnerability

By Published On: September 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Cisco Secure Workload Unauthorized API Access Vulnerability


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Systems Affected


Cisco Secure Workload Cluster Software

Overview


A vulnerability has been reported in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.


Target Audience: 

All IT administrators and individuals responsible for maintaining and updating in Software.


Risk Assessment:

High risk of data manipulation and service disruption.


Impact Assessment:

Potential impact on confidentiality, integrity, and availability of the system.


Description


This vulnerability exists due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint.


Successful exploitation of this vulnerability could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user.


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy


CVE Name

CVE-2026-20223




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZieEACgkQ3jCgcSdc

ys8Lxg//dl0afolF8KF3qFEpO07g4B/W8Pr2BmCELc9zBzcA19pfC+gj0vhBDFZ/

2tEt+kgBYv6aabUX2cGYEUnUOzWtVELWEoR+Z3JIbiXoCihPfy+Q54boy4LcC73f

flEfILghKVaHAv9Vm/nduUxpOg02/BFYEuw8Cjg65JoL11G9+IRK7Wq5a27XmWju

DrBQN0fxP3dc5gOoU3BbvoN1i2w/j5rTI0D7LJJumNm9+97TmDPqBIdOuXwo6Iw5

doHSXiC66SoRxr/F2PxaU06kzPiyS5dZErq55kATSxoWPxfk/6yEFlvFkd6YeC6H

xAwAmwYomTQj0WC4I+q307dfrHLQjxA6AJL9OSzpkXqa/cjXyBRCLu73XO9Ps0oB

VGV0+KXfiL5r3Nj1JUv7j2pG+lwkRObbe/qPdqI/ELFZkS1RLfXhc3WGHv0bfYrc

KbCUX+Dw+OZHqLkOAi5pYuuWEw/LzZ+yI5g3Tw7zcVVv5WAjLQZ3ra6Cu1s5O0mA

MxOaZyy6GHBp7lDhvmOlKDBY+FPr7y/Jf749l0LXn//BvTO43yv+cSpID/8OEewR

Qv+E5fdT+E/vUS7rmH55hMU0XopL3h8xAw+p96FEBoOQjmSKkefH4UyfAplSTpDG

QQOgxvr/Dv0zxCbxZX+BOXe+Ofg329VRCuW5VtRG/YJqQp9rc7U=

=MYMV

—–END PGP SIGNATURE—–

Share this article