CVE-2026-41187
EUVD-2026-5115430.07.2026, 15:16
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tigera | calico | 𝑥 < 3.31.6 | CNA |
| tigera | calico | 3.32.0 ≤ 𝑥 < 3.32.1 | CNA |
| tigera | calico | 𝑥 < 3.21.7 | CNA |
| tigera | calico | 3.22.0 ≤ 𝑥 < 3.22.5 | CNA |
| tigera | calico | 𝑥 < 22.4.0 | CNA |
Common Weakness Enumeration