CVE-2026-49445: Cilium
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
Affected products
- Cilium Cilium: before 1.17.14 (fixed in 1.17.14); from 1.18.0, before 1.18.8 (fixed in 1.18.8); from 1.19.0, before 1.19.2 (fixed in 1.19.2)
Published 2026-07-15. Last modified 2026-07-17.