Authorization Bypass in Calico's Network Policy Management
CVE-2026-41187

6.2MEDIUM

Key Information:

Vendor

Tigera

Vendor
CVE Published:
30 July 2026

What is CVE-2026-41187?

Calico's API server implementation contains a vulnerability where the Delete override for NetworkPolicy and GlobalNetworkPolicy does not execute during DeleteCollection requests. This oversight allows users with the deletecollection verb or wildcard permissions on tier-scoped resources to perform bulk deletions of policies across tiers without appropriate access rights, thereby undermining the intended tier authorization boundaries. Immediate attention to patch this issue is crucial to maintain security within tiered policy management.

Affected Version(s)

Calico 0 < 3.31.6

Calico 3.32.0 < 3.32.1

Calico Cloud 0 < 22.4.0

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Behnam Shobiri
Mazdak Nasab
Anthony Tam
Matt Dupre
.