No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Kubernetes API bearer token, etcd password, and inline PEM-encoded etcd client certificate and key. Any reader of that stderr stream — CI job logs, session-recording archives, shared support-ticket transcripts, or local filesystem viewers on the host that ran calicoctl — can extract these credentials with zero Kubernetes privilege. calicoctl's default log level is panic, so this issue only triggers when verbose logging is explicitly enabled. | |
| Title | Calicoctl leaks cluster credentials to stderr when verbose logging is enabled | |
| First Time appeared |
Tigera
Tigera calico Tigera calico Cloud Tigera calico Enterprise |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:tigera:calico:*:*:*:*:*:*:*:* cpe:2.3:a:tigera:calico_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:tigera:calico_enterprise:*:*:*:*:*:*:*:* cpe:2.3:a:tigera:calico_enterprise:3.22.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tigera
Tigera calico Tigera calico Cloud Tigera calico Enterprise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Tigera
Published:
Updated: 2026-05-28T17:04:11.659Z
Reserved: 2026-04-20T19:31:31.065Z
Link: CVE-2026-6720
Updated: 2026-05-28T17:04:08.496Z
Status : Received
Published: 2026-05-28T17:16:33.490
Modified: 2026-05-28T17:16:33.490
Link: CVE-2026-6720
No data.
OpenCVE Enrichment
No data.