CVE-2026-41187Medium· 6.5▾ SunlitCalico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requ…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.
calico < 3.21.7calico < 3.31.6calico <= 22.4.0calico >= 3.22.0, < 3.22.4calico >= 3.32.0, < 3.32.1Upgrade past the affected range:
calico 3.32.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6540High· 7.5Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization
CVE-2026-41186High· 7.5When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication
CVE-2026-93954Medium· 4.3A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1
CVE-2026-43695Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-54766MediumVikunja is an open-source self-hosted task management platform
CVE-2026-14538High· 7.7An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation che…