Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Version 1.15.3 contains a patch for this issue. There are no known workarounds.
Cite this page
CVE-2022-39388. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-39388
Use CWE-863, Istio vendor hub and Istio product page to widen CVE-2022-39388 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-31837 and CVE-2021-39156 for nearby disclosures in the same product family.