CVE-2026-49445
published 2026-07-15CVE-2026-49445: Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or…
PriorityP348high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.17%
6.2th percentile
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | < 1.17.14 | 1.17.14 |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.18.0 < 1.18.8 | 1.18.8 |
| cilium | cilium | >= 1.19.0 < 1.19.2 | 1.19.2 |
| github.com | cilium_cilium | >= 0 < 1.17.14 | 1.17.14 |
| github.com | cilium_cilium | >= 1.18.0 < 1.18.8 | 1.18.8 |
| github.com | cilium_cilium | >= 1.19.0 < 1.19.2 | 1.19.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cilium up to 1.17.13/1.18.7/1.19.1 Admin Endpoints admin.sock improper authentication
vuldb·2026-07-15·CVSS 9.2
CVE-2026-49445 [CRITICAL] Cilium up to 1.17.13/1.18.7/1.19.1 Admin Endpoints admin.sock improper authentication
A vulnerability classified as very critical has been found in Cilium up to 1.17.13/1.18.7/1.19.1. The affected element is an unknown function of the file admin.sock of the component Admin Endpoints. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-49445. The attack can only be performed from a local environment. No exploit is available.
GHSA
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
ghsa·2026-07-06
CVE-2026-49445 [CRITICAL] CWE-862 Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
### Impact
When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:
- Exposing TLS secrets
- Disrupting traffic in the cluster
- Terminating the Envoy process
This issue affects both the embedded and standalone Envoy deployment models.
### Patches
This issue affects:
- Cilium v1.19 between v1.19.0 and v1.19.1 inclusive
- Cilium v1.18 between v1.18.0 and v1.18.7 inclusive
- All versi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/cilium/cilium/commit/7bfbdd5c1be83d6c9ba3e089b4c804b6603505b6https://github.com/cilium/cilium/pull/44512https://github.com/cilium/cilium/releases/tag/v1.17.14https://github.com/cilium/cilium/releases/tag/v1.18.8https://github.com/cilium/cilium/releases/tag/v1.19.2https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9
2026-07-15
Published