๐Ÿ” CVE Alert

CVE-2026-41187

UNKNOWN 0.0

Calico Tier Authorization Bypass via DeleteCollection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.

CWE CWE-285 CWE-863
Vendor tigera
Product calico
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for tigera calico

Be the first to know when new unknown vulnerabilities affecting tigera calico are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tigera / Calico
0 < 3.31.6 3.32.0 < 3.32.1
Tigera / Calico Enterprise
0 < 3.21.7 3.22.0 < 3.22.5
Tigera / Calico Cloud
0 < 22.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/projectcalico/calico/pull/12731 github.com: https://github.com/projectcalico/calico/pull/12735 github.com: https://github.com/projectcalico/calico/pull/12736 github.com: https://github.com/projectcalico/calico/pull/12737 tigera.io: https://www.tigera.io/security-bulletins/tta-2026-006/

Credits

Behnam Shobiri Mazdak Nasab Anthony Tam Matt Dupre