Sensitive Data Exposure in Cilium Networking Solution
CVE-2026-41520

7.9HIGH

Key Information:

Vendor

Cilium

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-41520?

Cilium, a prominent networking and security solution, is affected by a vulnerability that exposes sensitive data when the cilium-bugtool is executed on deployments utilizing WireGuard encryption. This issue may inadvertently reveal critical information through the tool's output, posing a risk to the security and privacy of the data involved. It has been addressed in versions 1.17.15, 1.18.9, and 1.19.3.

Affected Version(s)

cilium < 1.17.15 < 1.17.15

cilium >= 1.18.0, < 1.18.9 < 1.18.0, 1.18.9

cilium >= 1.19.0, < 1.19.3 < 1.19.0, 1.19.3

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.