CVE-2026-41187
Calico Tier Authorization Bypass via DeleteCollection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.
| CWE | CWE-285 CWE-863 |
| Vendor | tigera |
| Product | calico |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for tigera calico
Be the first to know when new unknown vulnerabilities affecting tigera calico are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Tigera / Calico
0 < 3.31.6 3.32.0 < 3.32.1
Tigera / Calico Enterprise
0 < 3.21.7 3.22.0 < 3.22.5
Tigera / Calico Cloud
0 < 22.4.0
References
github.com: https://github.com/projectcalico/calico/pull/12731 github.com: https://github.com/projectcalico/calico/pull/12735 github.com: https://github.com/projectcalico/calico/pull/12736 github.com: https://github.com/projectcalico/calico/pull/12737 tigera.io: https://www.tigera.io/security-bulletins/tta-2026-006/
Credits
Behnam Shobiri Mazdak Nasab Anthony Tam Matt Dupre