Summary
CVE-2026-20315 is a critical improper access control vulnerability (CWE-284) in Cisco Secure Workload, discovered by Cisco during an internal security review and disclosed as part of an August 2026 security hardening release. The flaw affects both SaaS and on-premises Secure Workload deployments and carries the maximum CVSS score of 10.0. Cisco states it is not aware of any public announcements or malicious use of this vulnerability.
Technical details
- Root cause: Improper access control (CWE-284) within Cisco Secure Workload, covering authorization, authentication, privilege, and bypass weaknesses grouped under this single CVE.
- Trigger conditions: No authentication or user interaction is required to trigger the issue (PR:N, UI:N).
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), exploitable remotely against exposed Secure Workload deployments.
- Impact: Scope is changed (S:C), with high impact to confidentiality, integrity, and availability, indicating the vulnerability can affect resources beyond the vulnerable component itself.
- Affects both SaaS and on-premises deployments, regardless of device configuration.
Affected software
- Cisco Secure Workload releases 3.10 and earlier, including versions spanning the 1.x, 2.x, and 3.x lines (e.g., 1.102.21 through 3.10.x)
- Cisco Secure Workload release 4.0, up to and including 4.0.3.17
- Cluster, Agent, and Connector software components all require upgrading to fully remediate the vulnerability
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Cisco Secure Workload release 3.10 and earlier to 3.10.9.1, and release 4.0 to 4.0.4.16.
- For SaaS deployments, Cisco has already upgraded the Cluster software; customers only need to upgrade the Agent and Connector software.
- No workarounds are available for this vulnerability — software upgrade is the only remediation path.
- Contact Cisco TAC or your contracted maintenance provider for assistance with upgrade planning.

