
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26963 is a Host Policy bypass vulnerability in Cilium, the eBPF-based Kubernetes networking and security platform. When Native Routing, WireGuard, and Node Encryption (beta) are all simultaneously enabled, Host Policies incorrectly permit traffic from Pods on other nodes, bypassing intended network segmentation. The vulnerability affects Cilium versions 1.18.0 through 1.18.5 inclusive; all three triggering options are disabled by default. It was published on February 19, 2026, with a CVSS v3.1 score of 6.1 (Moderate) per the GitHub Advisory, classified as CWE-863 (Incorrect Authorization) (GitHub Advisory, Cilium Advisory).
The root cause (CWE-863: Incorrect Authorization) lies in the eBPF program bpf_wireguard.c, which erroneously returned all packets destined for the local host directly to the network stack without routing them through cilium_host for Host Firewall (HostFw) policy enforcement. Specifically, when decrypted WireGuard traffic arrived on the cilium_wg0 interface, the BPF program skipped the to-host program in cilium_host@ingress that enforces Host Policies, allowing cross-node Pod traffic to bypass ingress policy checks. The fix (PR #42892, commit 88e28e1) ensures that packets destined for the local host are always redirected to cilium_net@egress (and subsequently through cilium_host@ingress), restoring HostFw enforcement for WireGuard-decrypted traffic. Exploitation requires an adjacent network position and all three non-default features to be simultaneously active (Cilium Commit, Cilium PR #42892).
An attacker positioned on an adjacent network (e.g., another Pod on a different node within the same cluster) could send traffic that bypasses Host Policies and reaches Pods or the host on other nodes without authorization. This results in low confidentiality impact (unauthorized access to pod communications and potential data interception) and low integrity impact (potential unauthorized data modification across node boundaries), with no availability impact. The vulnerability undermines network segmentation and pod isolation in multi-node Cilium deployments that rely on Host Policies for security enforcement (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.007% (0th percentile), indicating a very low probability of exploitation in the near term. Exploitation is constrained by the requirement that all three non-default features — Native Routing, WireGuard, and Node Encryption (beta) — must be simultaneously enabled, significantly limiting the attack surface (GitHub Advisory, Feedly).
cilium_wg0 is not routed through cilium_host@ingress for policy enforcement in vulnerable versions, the traffic passes through without being subject to Host Firewall rules.cilium_wg0 that is not subject to HostFw enforcement in Cilium flow logs.FORWARDED under Host Policy rules; absence of policy drop events for traffic that should be denied.--enable-wireguard, --enable-node-encryption, and native routing mode all active on versions 1.18.0–1.18.5 should be treated as potentially affected.The primary remediation is to upgrade Cilium to version 1.18.6 or later, which contains the fix in commit 88e28e1 (Cilium v1.18.6 Release). As a temporary workaround (validated only in local Kind environments — not exhaustively tested in production), route all ingress traffic from cilium_wg0 through cilium_host on each CiliumNode:
# IPv4
ip rule add iif cilium_wg0 table 300
ip route add default dev cilium_host table 300
# IPv6
ip -6 rule add iif cilium_wg0 table 300
ip -6 route add default dev cilium_net table 300Alternatively, disable one or more of the three triggering features (Native Routing, WireGuard, or Node Encryption beta) if not strictly required (GitHub Advisory, Cilium Advisory).
The vulnerability was reported by @julianwiedmann and fixed by @smagnani96 (Simone Magnani) of the Cilium project, with the advisory published by @ferozsalam on February 19, 2026. The fix was noted in the Azure AKS release notes for March 5, 2026, indicating uptake by managed Kubernetes providers. The issue was also picked up by SUSE's govulncheck vulnerability database and the Linux Security advisories feed, reflecting standard industry tracking of the disclosure (Cilium PR #42892, Cilium v1.18.6 Release).
Fix availability across major Linux distributions and their releases.
devel
golang-github-cilium-ebpf
jammy
golang-github-cilium-ebpf
jammy (esm-apps)
golang-github-cilium-ebpf
noble
golang-github-cilium-ebpf
noble (esm-apps)
golang-github-cilium-ebpf
resolute
golang-github-cilium-ebpf
resolute (esm-apps)
golang-github-cilium-ebpf
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."