CVE-2026-20223

CRITICAL

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp...

Affects 0 products across 2 vendors.

BCS6.89
CVSS 3.110.0
EPSS0.8%
Percentile54th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the access validation of internal REST APIs of Cisco Secure Workload allows unauthenticated, remote attackers to access site resources with Site Admin privileges.

BSID: BS-2026-GLOBAL-271074-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20223?
A critical vulnerability in the access validation of internal REST APIs of Cisco Secure Workload allows unauthenticated, remote attackers to access site resources with Site Admin privileges.
What is the CVSS score for CVE-2026-20223?
CVE-2026-20223 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. EPSS: 0.8%.
Is CVE-2026-20223 actively exploited?
No confirmed active exploitation of CVE-2026-20223 as of 2026-07-01.
How do I remediate CVE-2026-20223?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy PSIRT: [email protected]
What systems are affected by CVE-2026-20223?
CVE-2026-20223 affects: Cisco, Francisco Burzi.
Vulnerability Details
CVE IDCVE-2026-20223
BSIDBS-2026-GLOBAL-271074-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Published2026-05-20
Last Modified2026-06-30
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability stems from insufficient validation and authentication mechanisms when accessing REST API endpoints. An attacker can exploit this by sending crafted requests to the affected APIs.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco —
Francisco Burzi —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 75 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hasha3613924aa19c393f94fedb6d97f30e5377585374cac7c24ee36b746650a77178deb31cd36fde7a5cb908b3c53aec7937f72ad056b424862774906c06108b89d
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2014-0659 10.0 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N rout... CVE-2014-0648 10.0 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 ... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →