Database/Container, Kubernetes & orchestration
Cilium: With L7 enabled, the embedded Envoy exposes a world-accessible admin.sock on the cluster
CVSS 9.2CVE-2026-49445Container, Kubernetes & orchestrationcurated
Impact
With L7 enabled, the embedded Envoy exposes a world-accessible admin.sock on the cluster; full dataplane control
Who can reach it
Any pod on the cluster network
What to do
Emergency rolling Cilium upgrade; no GPU drain but expect brief dataplane blips per node
References
Related entries
- Cilium: Incorrect default permissions on Cilium-managed host paths allow privilege escalationCVE-2022-29178 · CiliumHigh
- Cilium: IPsec transparent encryption is cryptographically ineffectiveCVE-2024-28860 · CiliumHigh
- Cilium: cilium-bugtool output contains sensitive dataCVE-2024-37307 · CiliumHigh
- Cilium: cilium-bugtool leaks sensitive data (recurrence of the 2024 issue)CVE-2026-41520 · CiliumHigh
- Cilium: An attacker able to update pod labels causes Cilium to apply the wrong network policyCVE-2023-39347 · CiliumHigh
- Cilium: After a container escape, an attacker can install eBPF programs and take over the node dataplaneCVE-2022-29179 · CiliumHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.