
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41520 is an information disclosure vulnerability in Cilium's cilium-bugtool debugging utility that exposes WireGuard private keys (cilium_wg0.key) when run against Cilium deployments with WireGuard Transparent Encryption enabled. The vulnerability affects all Cilium versions prior to v1.17.15, v1.18.0 through v1.18.8, and v1.19.0 through v1.19.2. It was reported by @kodareef5, published to the GitHub Advisory Database on April 25, 2026, and patched on the same date. The CVSS v3.1 score is 7.9 (High) per the GitHub Security Advisory, though NVD scores it at 4.4 (Medium) using a narrower vector (Github Advisory, Cilium Advisory).
The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-312 (Cleartext Storage of Sensitive Information). When cilium-bugtool collects diagnostic data from a Cilium node with WireGuard encryption enabled, it inadvertently includes the WireGuard private key file (cilium_wg0.key) in the generated debug archive without sanitizing or excluding cryptographic key material. This tool is also invoked automatically by the Cilium CLI's cilium sysdump command, meaning any operator or privileged user who runs a sysdump on an affected node and shares the resulting archive exposes the node's WireGuard private key to unintended recipients (Github Advisory, Cilium Advisory).
Exposure of the WireGuard private key (cilium_wg0.key) from a debug archive compromises the confidentiality of node-to-node encrypted communications within the Cilium cluster. An attacker who obtains the archive — for example, through insecure sharing of support bundles — could use the private key to decrypt WireGuard-encrypted traffic between cluster nodes, effectively breaking the transparent encryption layer. There is no direct integrity or availability impact, but the confidentiality breach could enable passive decryption of inter-node traffic and potentially facilitate lateral movement within the cluster (Github Advisory).
There is no known public exploit code or evidence of in-the-wild exploitation for this vulnerability. The EPSS score is approximately 0.006% (0th percentile), indicating a very low probability of near-term exploitation (Github Advisory). Exploitation requires local, high-privilege access to invoke cilium-bugtool or cilium sysdump, and the actual risk materializes only if the resulting archive is shared with an unauthorized party. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
cilium-bugtool directly on the affected node, or use the Cilium CLI command cilium sysdump to generate a diagnostic archive. Both commands collect system state and include the WireGuard key file..tar.gz file) and locate the cilium_wg0.key file, which contains the WireGuard private key for that node in cleartext.cilium-bugtool output archives (.tar.gz) containing a cilium_wg0.key file on affected nodes or in shared storage locations; unexpected copies of WireGuard key files outside of their expected system paths.cilium-bugtool or cilium sysdump commands by unexpected users or at unexpected times; file access logs showing reads of /var/lib/cilium/cilium_wg0.key or equivalent paths during bugtool execution.Upgrade Cilium to a patched version: v1.17.15, v1.18.9, or v1.19.3, which exclude the WireGuard private key from cilium-bugtool output (Cilium v1.17.15, Cilium v1.18.9, Cilium v1.19.3). There is no configuration-based workaround available. Users who have previously shared bugtool or sysdump archives from WireGuard-enabled nodes should immediately rotate the WireGuard keys on affected nodes by deleting the cilium_wg0.key file and restarting the Cilium agent, which will generate a new key pair (Github Advisory).
The Cilium community, in collaboration with members of Isovalent, coordinated the disclosure and remediation of this issue. The advisory credits @kodareef5 for responsible disclosure and @tklauser for triaging and remediating the vulnerability. No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory (Cilium Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."