CVE-2026-49445

CRITICAL

Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access

Title source: cna
STIX 2.1

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.

Scores

CVSS v3 9.2
EPSS 0.0013
EPSS Percentile 2.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
cilium/cilium < 1.17.14 (2 CPE variants)
cilium/cilium >= 1.18.0, < 1.18.8
cilium/cilium >= 1.19.0, < 1.19.2
Published Jul 15, 2026
Tracked Since Jul 16, 2026