Improper access control in CNI Plugins - CVE-2025-67499

 

Improper access control in CNI Plugins - CVE-2025-67499

Published: January 8, 2026


Vulnerability identifier: #VU121094
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67499
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the portmap plugin using the nftables backend, which forwards traffic based only on the destination port. A local user can intercept all traffic destined for that port.


Affected software

CNI Plugins

How to mitigate CVE-2025-67499

Install updates from vendor's website.

CNI Plugins - update to 1.9.0

External References

Related Security Bulletins