Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:* cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:* cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:* |
|
| Metrics |
cvssV3_1
|
Thu, 28 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the token to any authenticated user with pods/log permission in the namespace with calico-node. The token holds patch privileges on pods/status, enabling annotation-based attacks against cluster workloads. The default kubeconfig-based authentication path is not affected. This is a direct regression of TTA-2018-001. | |
| Title | ServiceAccount token disclosure via install-cni container logs | |
| First Time appeared |
Tigera
Tigera calico |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:tigera:calico:*:*:*:*:*:*:*:* cpe:2.3:a:tigera:calico:3.32.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tigera
Tigera calico |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Tigera
Published:
Updated: 2026-05-28T17:04:36.059Z
Reserved: 2026-04-17T17:41:35.905Z
Link: CVE-2026-41184
Updated: 2026-05-28T17:04:33.558Z
Status : Analyzed
Published: 2026-05-28T17:16:22.270
Modified: 2026-06-05T17:05:19.253
Link: CVE-2026-41184
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:00:16Z