Back to Blog
Cybersecurity May 23, 2026 5 min read

CVE-2026-20223 (CVSS 10.0): Cisco Secure Workload Flaw Grants Unauthenticated Site Admin Access

A perfect-score vulnerability in Cisco Secure Workload lets any unauthenticated attacker assume Site Admin privileges over enterprise data center segmentation policy. Patch to 3.10.8.3 or 4.0.3.17 immediately.

CVE-2026-20223 (CVSS 10.0): Cisco Secure Workload Flaw Grants Unauthenticated Site Admin Access

Cisco disclosed CVE-2026-20223 on May 20–22, 2026 — a maximum-severity vulnerability in Cisco Secure Workload earning a perfect CVSS score of 10.0. The flaw sits in internal REST API endpoints where insufficient authentication and validation allow a completely unauthenticated remote attacker to cross tenant isolation boundaries and claim Site Admin privileges, the highest privilege level in the system.

The CVSS vector leaves nowhere to hide: Attack Vector: NETWORK / Attack Complexity: LOW / Privileges Required: NONE / User Interaction: NONE / Scope: CHANGED / Confidentiality: HIGH / Integrity: HIGH / Availability: HIGH. No credentials. No phishing. No foothold on the internal network. An attacker with basic network connectivity to the management plane can send a crafted API request and own the system.

What an attacker gains

Cisco Secure Workload enforces zero-trust micro-segmentation policy across enterprise data centers and cloud environments. A Site Admin can:

  • Read sensitive configuration data across all tenants on the platform
  • Modify workload segmentation policies — allowing lateral movement that the product is specifically designed to prevent
  • Push changes to connected data center infrastructure and cloud workload definitions

In practice, exploiting this bug dismantles the zero-trust segmentation that organizations rely on to contain breaches.

Affected versions and the fix

Both SaaS-hosted and on-premises deployments are affected. Fixed versions are:

  • 3.10.8.3 — upgrade from any 3.x release
  • 4.0.3.17 — upgrade from any 4.0.x release

Release 3.9 and earlier have no patch path and must migrate to a supported release before applying the fix. Cisco’s PSIRT stated no active exploitation was observed at the time of disclosure.

“No active exploitation observed” is a 72-hour window, not a guarantee. CVSS 10.0 bugs are reverse-engineered from patch diffs within days of release, and Cisco has been hit with multiple perfect-score disclosures in the past 18 months — CVE-2026-20223 will be no different once the exploit researcher community finishes their analysis.

Prioritize this patch

If your organization runs Cisco Secure Workload, this is a P0 emergency patch regardless of whether exploitation has been confirmed. The blast radius of a successful exploit — full segmentation policy takeover across an entire enterprise environment — makes waiting unjustifiable.

Check the Cisco Security Advisory for full patch instructions and indicators of compromise. Enable network-level access controls on the Secure Workload management plane as a compensating control if immediate patching is not possible.

cisco cve cvss10 enterprise-security zero-trust