CVE-2026-49445 cilium vulnerability
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.
Browse Privilege Escalation security risksQuick answer
cilium should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.
Who is affected
Affected versions
- < 1.17.14
- >= 1.18.0, < 1.18.8
- >= 1.19.0, < 1.19.2
Fixed versions
- 1.17.14
- 1.18.8
- 1.19.2
How to fix it
Cilium is affected by CVE-2026-49445, a world-accessible local Envoy admin socket when L7 features are enabled. A local attacker can read TLS secrets, disrupt cluster traffic, call Envoy admin functions, or terminate Envoy. Upgrade Cilium to 1.17.14, 1.18.8, 1.19.2, or a later supported patched version for the installed branch. Treat exposed production systems as an urgent patch and incident-review priority.
- Inventory every Cilium deployment, version, exposed endpoint, environment, and owner.
- Check every node where Cilium L7 is enabled, including both embedded and standalone Envoy deployment models.
- Upgrade Cilium to 1.17.14, 1.18.8, 1.19.2, or a later supported patched version for the installed branch.
- The vendor lists no workaround, so prioritize the upgrade and tightly limit local node access until it is complete.
- Review local access, Envoy admin endpoint use, unexpected restarts, traffic disruption, and reads of the admin socket or TLS secret endpoints.
- Rotate TLS material and node or workload credentials if unauthorized socket access is found, then restore affected traffic policy.
- Restart or redeploy affected services when required, remove temporary artifacts, and keep compensating controls until validation is complete.
Scan now. Google sign-in is only needed to unlock fix guidance.
Verify the fix
- Confirm every Cilium deployment is on 1.17.14, 1.18.8, 1.19.2, or a later supported patched release for its branch; restricting local node access alone is not remediation.
- Confirm the Envoy admin socket is mode 0660 with the expected owner and group on every node, an unrelated local user cannot connect, and L7 traffic still works.
- Confirm Cilium RBAC, network policy, Gateway API objects, node access, and local socket permissions match the cluster's approved security baseline.
- Review logs after remediation for continued exploit attempts or signs that the issue was used before the fix.
- Rerun the relevant dependency, platform, vendor, or Fixnx security check and document the result, affected assets, change record, and cleanup evidence for CVE-2026-49445.
Related categories
Related security risks
More published guidance from the same primary category.
CVE-2026-65897 grav vulnerability
Updated July 24, 2026
mediumCVE-2026-65010 datasets vulnerability
Updated July 24, 2026
highWPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update
Updated July 24, 2026
Trusted references
FAQ
What is affected by CVE-2026-49445?
cilium versions listed as affected should be reviewed: < 1.17.14, >= 1.18.0, < 1.18.8, >= 1.19.0, < 1.19.2.
What should I fix first?
Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.
How do I confirm the fix worked?
Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.
How are Fixnx security risk categories chosen?
Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.
