CVE-2026-26963: 
Cilium vulnerability analysis and mitigation

Overview

CVE-2026-26963 is a Host Policy bypass vulnerability in Cilium, the eBPF-based Kubernetes networking and security platform. When Native Routing, WireGuard, and Node Encryption (beta) are all simultaneously enabled, Host Policies incorrectly permit traffic from Pods on other nodes, bypassing intended network segmentation. The vulnerability affects Cilium versions 1.18.0 through 1.18.5 inclusive; all three triggering options are disabled by default. It was published on February 19, 2026, with a CVSS v3.1 score of 6.1 (Moderate) per the GitHub Advisory, classified as CWE-863 (Incorrect Authorization) (GitHub Advisory, Cilium Advisory).

Technical details

The root cause (CWE-863: Incorrect Authorization) lies in the eBPF program bpf_wireguard.c, which erroneously returned all packets destined for the local host directly to the network stack without routing them through cilium_host for Host Firewall (HostFw) policy enforcement. Specifically, when decrypted WireGuard traffic arrived on the cilium_wg0 interface, the BPF program skipped the to-host program in cilium_host@ingress that enforces Host Policies, allowing cross-node Pod traffic to bypass ingress policy checks. The fix (PR #42892, commit 88e28e1) ensures that packets destined for the local host are always redirected to cilium_net@egress (and subsequently through cilium_host@ingress), restoring HostFw enforcement for WireGuard-decrypted traffic. Exploitation requires an adjacent network position and all three non-default features to be simultaneously active (Cilium Commit, Cilium PR #42892).

Impact

An attacker positioned on an adjacent network (e.g., another Pod on a different node within the same cluster) could send traffic that bypasses Host Policies and reaches Pods or the host on other nodes without authorization. This results in low confidentiality impact (unauthorized access to pod communications and potential data interception) and low integrity impact (potential unauthorized data modification across node boundaries), with no availability impact. The vulnerability undermines network segmentation and pod isolation in multi-node Cilium deployments that rely on Host Policies for security enforcement (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.007% (0th percentile), indicating a very low probability of exploitation in the near term. Exploitation is constrained by the requirement that all three non-default features — Native Routing, WireGuard, and Node Encryption (beta) — must be simultaneously enabled, significantly limiting the attack surface (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a vulnerable target: Confirm the target Cilium deployment is running versions 1.18.0–1.18.5 with Native Routing, WireGuard, and Node Encryption (beta) all enabled simultaneously.
  2. Gain adjacent network access: Obtain access to a Pod running on a different node within the same Kubernetes cluster (e.g., via a compromised workload or a legitimately scheduled Pod).
  3. Craft cross-node traffic: From the attacker-controlled Pod, send network traffic (TCP/UDP) destined for Pods or the host on another node that would normally be blocked by Host Policies.
  4. Bypass Host Policy enforcement: Because decrypted WireGuard traffic on cilium_wg0 is not routed through cilium_host@ingress for policy enforcement in vulnerable versions, the traffic passes through without being subject to Host Firewall rules.
  5. Achieve unauthorized access: The attacker's traffic reaches the target Pod or host, enabling unauthorized communication, data interception, or modification across node boundaries (Cilium PR #42892, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or unauthorized traffic flows between Pods on different nodes that should be blocked by Host Policies; cross-node traffic arriving on cilium_wg0 that is not subject to HostFw enforcement in Cilium flow logs.
  • Logs: Cilium Hubble flow logs showing traffic from remote Pod CIDRs reaching local host or Pod endpoints without a corresponding policy verdict of FORWARDED under Host Policy rules; absence of policy drop events for traffic that should be denied.
  • Configuration: Cilium deployments with --enable-wireguard, --enable-node-encryption, and native routing mode all active on versions 1.18.0–1.18.5 should be treated as potentially affected.

Mitigation and workarounds

The primary remediation is to upgrade Cilium to version 1.18.6 or later, which contains the fix in commit 88e28e1 (Cilium v1.18.6 Release). As a temporary workaround (validated only in local Kind environments — not exhaustively tested in production), route all ingress traffic from cilium_wg0 through cilium_host on each CiliumNode:

# IPv4
ip rule add iif cilium_wg0 table 300
ip route add default dev cilium_host table 300
# IPv6
ip -6 rule add iif cilium_wg0 table 300
ip -6 route add default dev cilium_net table 300

Alternatively, disable one or more of the three triggering features (Native Routing, WireGuard, or Node Encryption beta) if not strictly required (GitHub Advisory, Cilium Advisory).

Community reactions

The vulnerability was reported by @julianwiedmann and fixed by @smagnani96 (Simone Magnani) of the Cilium project, with the advisory published by @ferozsalam on February 19, 2026. The fix was noted in the Azure AKS release notes for March 5, 2026, indicating uptake by managed Kubernetes providers. The issue was also picked up by SUSE's govulncheck vulnerability database and the Linux Security advisories feed, reflecting standard industry tracking of the disclosure (Cilium PR #42892, Cilium v1.18.6 Release).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

devel

golang-github-cilium-ebpf

Unknown

jammy

golang-github-cilium-ebpf

Unknown

jammy (esm-apps)

golang-github-cilium-ebpf

Unknown

noble

golang-github-cilium-ebpf

Unknown

noble (esm-apps)

golang-github-cilium-ebpf

Unknown

resolute

golang-github-cilium-ebpf

Unknown

resolute (esm-apps)

golang-github-cilium-ebpf

Unknown

RHEL / CentOS

Affected

OpenShift

Not Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

Source: This report was generated using AI

Related Cilium vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56742HIGH8.9
  • Cilium logoCilium
  • hubble-1.16
NoYesJul 15, 2026
CVE-2026-49445HIGH8.8
  • Cilium logoCilium
  • cpe:2.3:a:cilium:cilium
NoYesJul 15, 2026
CVE-2026-53935MEDIUM6.9
  • Cilium logoCilium
  • kubescape-downloader
NoYesJul 07, 2026
CVE-2026-56743MEDIUM5.4
  • Cilium logoCilium
  • cilium-1.19
NoYesJul 15, 2026
CVE-2026-41520MEDIUM4.4
  • Cilium logoCilium
  • hubble-fips
NoYesMay 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management