Exploitable Namespace Management Flaw in Envoy Gateway Product by Envoy
CVE-2026-53718

6.4MEDIUM

Key Information:

Vendor

Envoyproxy

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-53718?

The Envoy Gateway has a vulnerability that allows an HTTPRoute to reference a backend resource from another namespace without appropriate authorization. This occurs due to a failure in validating the backend namespace, which violates the Gateway API's intended cross-namespace authorization model. This flaw enables route-owning namespaces to utilize backend resources without consent from the backend's namespace owner. The issue has been remediated in versions 1.7.4 and 1.8.1, where proper validation checks were implemented to enhance security and compliance with expected namespace permissions.

Affected Version(s)

gateway < 1.7.4 < 1.7.4

gateway >= 1.8.0-rc.0, < 1.8.1 < 1.8.0-rc.0, 1.8.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.