CVE-2026-49445
Cilium’s Envoy admin socket is world‑accessible when Layer‑7 functionality is enabled, letting a local attacker reach Envoy’s admin endpoints. This can expose TLS secrets, disrupt cluster traffic, or terminate Envoy. The flaw is critical because it requires only local access and has high impact on confidentiality and availability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Cilium networking, observability, and security solution – versions prior to 1.17.14, 1.18.8, and 1.19.2 when L7 functionality is enabled.
Real-world impact
A local attacker can access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy.
Why this severity
The CVSS score of 9.2 reflects local access with no authentication, high confidentiality impact, low integrity impact, and high availability impact, making it a critical vulnerability.
What to do about it
- 01Upgrade Cilium to version 1.17.14 or later, or 1.18.8 or later, or 1.19.2 or later.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/cilium/cilium/commit/7bfbdd…patch
- github.com/cilium/cilium/pull/44512patch
- github.com/cilium/cilium/releases/tag/…release notes
- github.com/cilium/cilium/releases/tag/…release notes
- github.com/cilium/cilium/releases/tag/…release notes
- github.com/cilium/cilium/security/advi…patchvendor advisory