CVE-2026-41187Disclosure(tigera / calico)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • calico

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
calico

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-08: 1Technical Details · 2026-08-08: 108-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    ☸️ Calico authorization boundary bypass CVE-2026-41187 affects Calico's API server. Users holding certain bulk-delete permissions can potentially use DeleteCollection to remove network policies from tiers they would otherwise not be authorized to modify. That could weaken or remove intended network-security controls. 🔎 Source: Calico / Tenable. #Kubernetes #Calico #NetworkSecurity #CVE #CyberSecurity

    Post summary

    The post reveals that CVE‑2026‑41187 enables users with bulk‑delete rights to remove otherwise protected network policies via DeleteCollection, potentially weakening security controls.

    0000045
    34 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Apptigeracalico---
Apptigeracalico---
Apptigeracalico---

Explore more