ServiceAccount token disclosure via Azure IPAM CNI plugin logs
Summary
| CVE | CVE-2026-41185 |
|---|---|
| State | PUBLISHED |
| Assigner | Tigera |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-28 17:16:22 UTC |
| Updated | 2026-05-28 18:55:06 UTC |
| Description | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unmarshaled configuration map (stdinData) at INFO level to /var/log/calico/cni/cni.log on every CNI ADD and DEL invocation — once per pod scheduled or terminated on the node. When the cluster is deployed using token-based Kubernetes authentication, this log entry contains the ServiceAccount token, client key, and certificate authority in plaintext. Any principal with read access to /var/log/calico/cni/cni.log on a node can read these logs and extract the credentials, which grant cluster-wide Calico networking admin privileges. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-532 | CWE-532 CWE-532 Insertion of sensitive information into log file
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
LowUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
LowSub Integrity
LowSub Availability
LowCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Tigera | Calico | affected 3.32.0 semver | Not specified |
| CNA | Tigera | Calico Enterprise | affected 3.21.7 semver | Not specified |
| CNA | Tigera | Calico Enterprise | affected 3.22.0 3.22.3 semver | Not specified |
| CNA | Tigera | Calico Cloud | affected 22.4.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/projectcalico/calico/pull/12526 | [email protected] | github.com | |
| github.com/projectcalico/calico/pull/12502 | [email protected] | github.com | |
| github.com/projectcalico/calico/pull/12527 | [email protected] | github.com | |
| www.tigera.io/security-bulletins/tta-2026-002 | [email protected] | www.tigera.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Behnam Shobiri (en)
CNA: Behnam Shobiri (en)
CNA: Anthony Tam (en)
CNA: Matt Dupre (en)
CNA: Casey Davenport (en)
There are currently no legacy QID mappings associated with this CVE.