CVE-2026-49445Disclosure(cilium / cilium)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cilium cilium systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cilium

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
cilium

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Cilium L7 exposes world-accessible Envoy admin socket (CVE-2026-49445) When Cilium L7 functionality is enabled, the Envoy instance on cluster nodes may create a world-accessible local admin socket, exposing Envoy’s admin endpoints in both embedded and standalone Envoy deployment models. The root cause is insecure default socket permissions / improper access control on a local administrative interface. An attacker with local access on a Kubernetes node (or any workload/user able to reach the socket path) can query Envoy admin endpoints without authorization and invoke administrative operations. Impact includes exposure of sensitive data (including TLS secrets) and disruptive actions such as terminating Envoy or manipulating traffic, leading to outage and potential compromise of service confidentiality. 👉 Affected: http://github.com/cilium/cilium (Cilium with L7 enabled) < 1.19.2, < 1.18.8, < 1.17.14 | Upgrade to 1.19.2 / 1.18.8 / 1.17.14

    Post summary

    A critical CVE in Cilium L7 exposes world‑accessible Envoy admin sockets; the post outlines the vulnerability details and urges users to upgrade to patched versions.

    0001091
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciliumcilium---

Explore more