CVE-2026-20223 is a critical authentication bypass vulnerability in Cisco Secure Workload Cluster Software affecting internal REST API access validation. The flaw is caused by insufficient validation and missing or inadequate authentication checks on affected API endpoints, allowing specially crafted requests to be processed without requiring valid credentials. Successful exploitation allows a remote unauthenticated attacker to access site resources with Site Admin privileges. In multitenant environments, the vulnerability can cross tenant boundaries, enabling unauthorized access to sensitive information and administrative configuration functions. The issue affects internal REST APIs rather than the web-based management interface and impacts both SaaS and on-premises deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone PoC repository for CVE-2026-20223 targeting Cisco Secure Workload. It contains 5 files total: a README and license, plus two executable PoC implementations—one in Python and one in Bash. The Python script defines a CiscoSecureWorkloadPoC class, sets up a requests session with TLS verification disabled, enumerates a list of privileged REST API endpoints, performs unauthenticated GET requests to identify exposed resources, and then attempts POST requests with JSON user-creation data when an endpoint appears accessible. It also includes a dedicated create_admin_user() routine that posts directly to /api/v1/users to create a Site Admin account. The Bash script mirrors the same logic using curl, logs results, stores temporary responses under /tmp, and tests one extra endpoint (/api/v1/config). Overall, the exploit capability is unauthorized access to privileged web API endpoints and potential unauthenticated creation of a high-privilege administrative user. This is not merely a detector: it includes active exploitation behavior via POST requests and hardcoded account-creation payloads, making it an operational PoC rather than a passive scanner.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability in the REST API of Cisco Secure Workload, categorized as CWE-306 and described as adjacent to broken authentication rather than BOLA.
Authentication bypass / missing authentication vulnerability in Cisco Secure Workload REST API that allows an unauthenticated remote attacker to access configuration and modify microsegmentation policies with Site Admin privileges across tenant boundaries.
A critical CVSS 10.0 authentication-related vulnerability in the internal APIs of Cisco Secure Workload that could expose a highly privileged zero-trust segmentation platform.
A critical authentication/authorization flaw in Cisco Secure Workload internal REST API endpoints that could allow an unauthenticated remote attacker to read sensitive information and make configuration changes across tenant boundaries with Site Admin-level privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.