CVE-2026-41187: Tigera Calico
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.
Affected products
- Tigera Calico: before 3.21.7 (fixed in 3.21.7); before 3.31.6 (fixed in 3.31.6); up to and including 22.4.0; from 3.22.0, before 3.22.4 (fixed in 3.22.4); from 3.32.0, before 3.32.1 (fixed in 3.32.1)
Published 2026-07-30. Last modified 2026-08-08.