CVE-2026-20317
Last modified
CVE-2026-20317 is a critical-severity vulnerability rated 10/10 on the CVSS scale. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are grouped under the Common Weakness Enumeration (CWE) CWE-287.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are grouped under the Common Weakness Enumeration (CWE) CWE-287.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Secure Workload | 2.2.1.41; 3.2.1.18; 3.3.2.50; 3.4.1.28; 3.4.1.34; 2.3.1.45; 2.3.1.41; 3.3.2.28; 3.1.1.59; 2.0.2.20; 2.1.1.33; 2.1.1.29; 3.2.1.28; 3.4.1.35; 3.1.1.65; 3.1.1.67; 2.0.1.34; 2.3.1.49; 2.2.1.39; 3.4.1.19; 3.3.2.23; 3.1.1.61; 3.1.1.54; 3.5.1.17; 3.3.2.33; 3.5.1.1; 2.3.1.53; 3.5.1.20; 3.5.1.30; 3.3.2.16; 3.1.1.55; 3.4.1.6; 2.3.1.50; 2.3.1.52; 3.2.1.19; 2.2.1.35; 3.1.1.53; 3.1.1.70; 3.2.1.20; 3.5.1.2; 1.103.1.12; 2.3.1.51; 3.3.2.42; 3.4.1.1; 3.3.2.12; 2.1.1.31; 3.5.1.23; 3.3.2.53; 3.4.1.14; 3.3.2.2; 3.4.1.20; 3.3.2.35; 2.2.1.34; 1.102.21; 3.3.2.5; 3.5.1.31; 3.6.1.5; 3.2.1.31; 3.5.1.37; 3.4.1.40; 3.6.1.17; 3.6.1.21; 3.2.1.32; 3.2.1.33; 3.6.1.35; 3.6.1.36; 3.7.1.5; 3.6.1.47; 3.7.1.22; 3.6.1.52; 3.7.1.39; 3.8.1.1; 3.7.1.51; 3.8.1.19; 3.8.1.36; 3.7.1.59; 3.8.1.39; 3.9.1.1; 3.9.1.10; 3.9.1.24; 3.9.1.25; 3.9.1.28; 3.9.1.38; 3.8.1.53; 3.9.1.52; 3.10.1.1; 3.9.1.64; 3.10.2.11; 3.9.1.66; 3.10.3.19; 3.9.1.69; 3.10.4.8; 3.10.5.6; 4.0.1.1; 4.0.2.4; 4.0.2.5; 3.10.6.3; 3.10.7.4; 4.0.3.13; 4.0.3.17; 3.10.8.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20317?
How severe is CVE-2026-20317?
How do I fix CVE-2026-20317?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20311A vulnerability in the web-based management interface of Cis…6.3
- CVE-2026-20312As part of Cisco's ongoing commitment to proactive security …8.8
- CVE-2026-20313As part of Cisco's ongoing commitment to proactive security …7.7
- CVE-2026-20314A vulnerability in Cisco Packaged Contact Center Enterprise …5
- CVE-2026-20315As part of Cisco's ongoing commitment to proactive security …10
- CVE-2026-20316A vulnerability in the web interface of Cisco Secure Firewal…5.3
- CVE-2026-20318As part of Cisco's ongoing commitment to proactive security …9.6
- CVE-2026-20319As part of Cisco's ongoing commitment to proactive security …7.5
- CVE-2026-2032Malicious scripts that interrupt new tab page loading could …4.3
- CVE-2026-20320A vulnerability in the Open Client Interface (OCI) XML Parse…7.5
- CVE-2026-20322As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-20323A vulnerability in the sftunnel inter-device communication p…8.3
Are you affected by CVE-2026-20317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
