CVE-2026-41187
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-285
Autorización incorrecta
Fecha de publicación:
30/07/2026
Última modificación:
08/08/2026
Descripción
*** Pendiente de traducción *** Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.
Impacto
Puntuación base 4.0
6.20
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:* | 3.21.7 (excluyendo) | |
| cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:* | 3.31.6 (excluyendo) | |
| cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:* | 22.4.0 (incluyendo) | |
| cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:* | 3.22.0 (incluyendo) | 3.22.4 (excluyendo) |
| cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:* | 3.32.0 (incluyendo) | 3.32.1 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



