CVE-2026-26308 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 Role-Based Access Control authorization (GHSA-ghc4-35x6-crw5 / WID-SEC-2026-0704)
A vulnerability marked as problematic has been reported in envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0. Impacted is an unknown function of the component Role-Based Access Control. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-26308. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.