PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73546 Envoyproxy CVE debrief

CVE-2026-73546 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The vulnerability affects Envoy's /stats?format=html admin endpoint, which can be exploited by an attacker to execute script with the admin interface's origin and issue privileged same-origin requests. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Vendor
Envoyproxy
Product
Envoy
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-10-05
Advisory published
2026-09-21
Advisory updated
2026-10-05

Who should care

Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names should assess exposure and prioritize remediation.

Why it matters

CVE-2026-73546 is a high-severity vulnerability in Envoy that allows for script execution with admin interface origin and privileged same-origin requests. Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names should assess exposure and prioritize remediation.

  • Script execution with admin interface origin
  • Privileged same-origin requests
  • Potential for data breaches or system compromise
  • Need for verification of affected versions and exposure

Technical summary

The /stats?format=html admin endpoint in Envoy uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests.

Defensive priority

Operators should assess exposure and prioritize remediation for Envoy instances with a browser-accessible admin interface and enabled components that persist attacker-influenced text in statistic names.

Recommended defensive actions

  • Assess exposure of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names.
  • Prioritize remediation for affected Envoy versions 1.36.0 to 1.36.9, 1.37.0 to 1.37.5, 1.38.0 to 1.38.3, and 1.39.0.
  • Verify and apply patches to upgrade to Envoy versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1.
  • Monitor and restrict access to the /stats?format=html admin endpoint.
  • Implement compensating controls, such as same-origin policy and Content Security Policy (CSP), to mitigate potential impacts.

Evidence notes

The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and the fixed versions. The vulnerability affects Envoy's /stats?format=html admin endpoint, which can be exploited by an attacker to execute script with the admin interface's origin and issue privileged same-origin requests. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenc

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73546 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73546

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73546 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73546

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.