What is CVE-2026-41187?
CVE-2026-41187 is a vulnerability in Calico's apiserver where the `DeleteCollection` requests bypass the `AuthorizeTierOperation` check for `NetworkPolicy`, `GlobalNetworkPolicy`, and their staged variants. This allows a user with `deletecollection` or a wildcard verb to perform unauthorized actions. Calico users should apply the latest updates to mitigate this issue.
Azərbaycanca: CVE-2026-41187 Calico-nun apiserver komponentində müəyyən edilmiş boşluqdur. Bu boşluq `DeleteCollection` sorğuları zamanı `NetworkPolicy`, `GlobalNetworkPolicy` və onların mərhələli variantları üzərində `AuthorizeTierOperation` yoxlanışını keçmir. Nəticədə `deletecollection` və ya wildcard icazəsinə malik istifadəçi səlahiyyətsiz icra apara bilər. Calico istifadəçiləri bu boşluğu aradan qaldıran yeniləmələri tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which Calico resources are affected by CVE-2026-41187?
This vulnerability affects `NetworkPolicy`, `GlobalNetworkPolicy`, and their staged variants.
What permissions does a malicious user need to exploit CVE-2026-41187?
Exploitation requires the user to have `deletecollection` or a wildcard verb permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.