CVE-2026-41184 Details
Description
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the token to any authenticated user with pods/log permission in the namespace with calico-node. The token holds patch privileges on pods/status, enabling annotation-based attacks against cluster workloads. The default kubeconfig-based authentication path is not affected. This is a direct regression of TTA-2018-001.
A vulnerability in Tigera Calico's CNI plugin allows for the unauthorized exposure of Kubernetes ServiceAccount bearer tokens. This issue arises because the install-cni init container logs the CNI configuration, including sensitive tokens, to standard output. The vulnerability is present in Calico deployments that use the __SERVICEACCOUNT_TOKEN__ placeholder, such as Canal and Flannel-Calico deployments. The exposed token grants patch privileges on pods/status, potentially enabling annotation-based attacks on cluster workloads. This vulnerability affects Calico versions 3.31 and 3.32.
Users can upgrade to Calico versions 3.31 or 3.32, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/projectcalico/calico/pull/12502 | [email protected] | Issue TrackingPatch |
| https://github.com/projectcalico/calico/pull/12526 | [email protected] | Issue TrackingPatch |
| https://github.com/projectcalico/calico/pull/12527 | [email protected] | Issue TrackingPatch |
| https://www.tigera.io/security-bulletins/tta-2026-001/ | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tigera calico | < 3.21.7 < 3.32.0 < 22.4.0 >= 3.22.0, < 3.22.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |