Authorization Bypass in Calico's Network Policy Management
CVE-2026-41187
6.2MEDIUM
Key Information:
- Vendor
Tigera
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2026-41187?
Calico's API server implementation contains a vulnerability where the Delete override for NetworkPolicy and GlobalNetworkPolicy does not execute during DeleteCollection requests. This oversight allows users with the deletecollection verb or wildcard permissions on tier-scoped resources to perform bulk deletions of policies across tiers without appropriate access rights, thereby undermining the intended tier authorization boundaries. Immediate attention to patch this issue is crucial to maintain security within tiered policy management.
Affected Version(s)
Calico 0 < 3.31.6
Calico 3.32.0 < 3.32.1
Calico Cloud 0 < 22.4.0
References
CVSS V4
Score:
6.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Behnam Shobiri
Mazdak Nasab
Anthony Tam
Matt Dupre
