Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41187.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "3.21.7"
},
{
"fixed": "22.4.0"
}
]
}
],
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"cna_assigner": "Tigera"
}{
"cpe": [
"cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:*",
"cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.31.6"
},
{
"introduced": "3.22.0"
},
{
"fixed": "3.22.4"
},
{
"introduced": "3.32.0"
},
{
"fixed": "3.32.1"
}
]
}