
☸️ Calico authorization boundary bypass CVE-2026-41187 affects Calico's API server. Users holding certain bulk-delete permissions can potentially use DeleteCollection to remove network policies from tiers they would otherwise not be authorized to modify. That could weaken or remove intended network-security controls. 🔎 Source: Calico / Tenable. #Kubernetes #Calico #NetworkSecurity #CVE #CyberSecurity
Post summary
The post reveals that CVE‑2026‑41187 enables users with bulk‑delete rights to remove otherwise protected network policies via DeleteCollection, potentially weakening security controls.
