Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
References
| Link | Resource |
|---|---|
| https://github.com/cilium/cilium/commit/7bfbdd5c1be83d6c9ba3e089b4c804b6603505b6 | Patch |
| https://github.com/cilium/cilium/pull/44512 | Patch |
| https://github.com/cilium/cilium/releases/tag/v1.17.14 | Release Notes |
| https://github.com/cilium/cilium/releases/tag/v1.18.8 | Release Notes |
| https://github.com/cilium/cilium/releases/tag/v1.19.2 | Release Notes |
| https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jul 2026, 17:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/cilium/cilium/commit/7bfbdd5c1be83d6c9ba3e089b4c804b6603505b6 - Patch | |
| References | () https://github.com/cilium/cilium/pull/44512 - Patch | |
| References | () https://github.com/cilium/cilium/releases/tag/v1.17.14 - Release Notes | |
| References | () https://github.com/cilium/cilium/releases/tag/v1.18.8 - Release Notes | |
| References | () https://github.com/cilium/cilium/releases/tag/v1.19.2 - Release Notes | |
| References | () https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9 - Patch, Vendor Advisory | |
| First Time |
Cilium
Cilium cilium |
|
| CPE | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* |
15 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 20:17
Updated : 2026-07-17 17:50
NVD link : CVE-2026-49445
Mitre link : CVE-2026-49445
CVE.ORG link : CVE-2026-49445
JSON object : View
Products Affected
cilium
- cilium
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
