CVE-2026-49445

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-15 20:17

Updated : 2026-07-17 17:50


NVD link : CVE-2026-49445

Mitre link : CVE-2026-49445

CVE.ORG link : CVE-2026-49445


JSON object : View

Products Affected

cilium

  • cilium
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource