Summary
CVE-2026-20317 is a critical improper authentication vulnerability (CWE-287) in Cisco Secure Workload, discovered by Cisco during an internal security review and disclosed as part of a broader Secure Workload security hardening release. The flaw allows an unauthenticated, remote attacker to bypass authentication over the network, and carries the maximum CVSS v3.1 base score of 10.0. Cisco states it is not aware of any public exploitation or proof-of-concept code for this issue.
Technical details
- Root cause: improper authentication handling (CWE-287) within Cisco Secure Workload’s software.
- Trigger conditions: no authentication or user interaction is required; the attacker needs only network access to a vulnerable Secure Workload deployment.
- Attack vector: network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), with a scope change (S:C) indicating impact beyond the vulnerable component.
- Impact: no confidentiality impact, but high integrity (I:H) and high availability (A:H) impact — consistent with an attacker being able to bypass authentication and alter or disrupt the system.
- This CVE was assigned as part of a grouped set of internally discovered vulnerabilities in the same Cisco Secure Workload hardening advisory (alongside separate command injection, access control, input validation, and buffer overflow issues tracked under other CVE IDs).
Affected software
- Cisco Secure Workload Software, on-premises deployments: versions 3.10 and earlier, and version 4.0 releases prior to the fix.
- Cisco Secure Workload Software as a Service (SaaS) deployments: Agent and Connector software prior to the fixed versions.
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Cisco Secure Workload to a fixed release — version 3.10.9.1 (for 3.10 and earlier) or version 4.0.4.16 (for 4.0). Cluster, Agent, and Connector software all require the update for on-premises deployments; SaaS customers only need to update Agent and Connector software.
- If no patch can be applied immediately: Cisco has stated there are no workarounds for this vulnerability, so network-level restriction of access to the Secure Workload management/API interfaces to trusted administrative networks is recommended as an interim compensating control until the upgrade is completed.

