SB2026010826 - Improper access control in CNI Plugins



SB2026010826 - Improper access control in CNI Plugins

Published: January 8, 2026

Security Bulletin ID SB2026010826
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2025-67499)

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the portmap plugin using the nftables backend, which forwards traffic based only on the destination port. A local user can intercept all traffic destined for that port.


Remediation

Install update from vendor's website.