Description

Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."

INFO

Published Date :

2026-01-15T19:18:50.806Z

Last Modified :

2026-01-15T19:47:53.919Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-23766 vulnerability.

Vendors Products
Istio
  • Istio
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact