Description
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unverified TLS
Action: Patch immediately
AI Analysis

Impact

Kuma is a modern Envoy‑based service mesh available for Kubernetes and VM workloads. Before releases 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, kumactl could be configured to communicate over HTTPS without supplying a CA certificate file. This disables TLS peer verification, allowing the client to accept any certificate, including forged or self‑signed ones, while sending API tokens over the unverified connection. An attacker who can observe the TLS traffic can intercept these tokens and impersonate the authenticated user, effectively gaining administrative control over the control plane. The default local profile is not affected because it uses plain HTTP.

Affected Systems

Versions of Kuma prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7 that use a customized kumactl profile configured for HTTPS without specifying --ca-cert-file are impacted. The default local profile is not affected because it communicates over plain HTTP. Any environment running those versions in a position where an attacker can reach the TLS connection is vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity vulnerability that can lead to loss of confidentiality and integrity but not necessarily availability. The EPSS score is < 1%, indicating the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector relies on a network adversary who can observe the traffic between kumactl and the control plane, which is plausible in shared or compromised network segments. Once the tokens are captured, the attacker can act as the authenticated user, signing requests, viewing data, or configuring the mesh. The default local profile uses plain HTTP and is not affected. Proper TLS verification mitigates the risk, and the issue is fixed in the specified releases.

Generated by OpenCVE AI on September 20, 2026 at 16:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade kumactl to at least version 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7, which include the fix for TLS peer verification
  • Ensure that any HTTPS control‑plane configuration includes a valid --ca-cert-file so that TLS certificates are verified
  • If upgrading immediately is not possible, restrict network access to the control‑plane endpoint to trusted hosts and monitor for TLS certificate mismatches

Generated by OpenCVE AI on September 20, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v95x-xhq5-4929 kumactl connects to control plane without verifying TLS certificate when no CA is configured
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Kumahq
Kumahq kuma
Vendors & Products Kumahq
Kumahq kuma

Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
Title Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:50:24.712Z

Reserved: 2026-06-03T20:54:20.433Z

Link: CVE-2026-50166

cve-icon Vulnrichment

Updated: 2026-09-16T15:50:17.569Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:16.950

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-50166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation