CVE-2022-39388
Istio Control Plane (istiod) vulnerability analysis and mitigation

Overview

Istio, an open platform for connecting, managing, and securing microservices, disclosed a vulnerability (CVE-2022-39388) affecting versions on the 1.15.x branch prior to 1.15.3. The vulnerability allows a user with localhost access to the Istiod control plane to impersonate any workload identity within the service mesh (Istio Advisory). The issue was patched in version 1.15.3, released on October 27, 2022 (Istio Release).

Technical details

The vulnerability is related to incorrect authorization (CWE-863) in the XFCC (X-Forwarded-Client-Cert) authenticator component. The CVSS v3.1 base score is 7.6 (High), with the following vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N. This indicates adjacent network attack vector, low attack complexity, low privileges required, no user interaction needed, changed scope, high confidentiality impact, low integrity impact, and no availability impact (NVD).

Impact

The vulnerability allows an attacker with localhost access to the Istiod control plane to impersonate any workload identity within the service mesh. This could lead to unauthorized access and potential security breaches within the service mesh environment (Istio Advisory).

Exploitability

The vulnerability requires the attacker to have localhost access to the Istiod control plane. The attack complexity is considered low, and no user interaction is needed for exploitation. The attacker needs low privileges to execute the attack (NVD).

Mitigation and workarounds

There are no known workarounds for this vulnerability. Users running affected versions (1.15.x branch prior to 1.15.3) should upgrade to version 1.15.3 or later to address this security issue (Istio Advisory).

Additional resources


SourceThis report was generated using AI

Related Istio Control Plane (istiod) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-31837HIGH8.7
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio-1.28
NoYesMar 10, 2026
CVE-2026-41413HIGH7.7
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • cpe:2.3:a:istio:istio
NoYesMay 07, 2026
CVE-2026-31838MEDIUM6.9
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio-1.29
NoYesMar 10, 2026
CVE-2026-39350MEDIUM5.4
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • istio.io/istio
NoYesApr 15, 2026
CVE-2026-23766NONEN/A
  • Istio Control Plane (istiod) logoIstio Control Plane (istiod)
  • cpe:2.3:a:istio:istio
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management