Vulnerabilities (CVE)

Filtered by vendor Cisco Subscribe
Filtered by product Secure Workload
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-20223 1 Cisco 1 Secure Workload 2026-07-23 N/A 10.0 CRITICAL
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 
CVE-2023-20136 1 Cisco 1 Secure Workload 2026-06-17 N/A 4.3 MEDIUM
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access control (RBAC) of certain OpenAPI operations. An attacker could exploit this vulnerability by issuing a crafted OpenAPI function call with valid credentials. A successful exploit could allow the attacker to execute OpenAPI operations that are reserved for the Administrator user, including the creation and deletion of user labels.