Impact
Kuma is a modern Envoy‑based service mesh available for Kubernetes and VM workloads. Before releases 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, kumactl could be configured to communicate over HTTPS without supplying a CA certificate file. This disables TLS peer verification, allowing the client to accept any certificate, including forged or self‑signed ones, while sending API tokens over the unverified connection. An attacker who can observe the TLS traffic can intercept these tokens and impersonate the authenticated user, effectively gaining administrative control over the control plane. The default local profile is not affected because it uses plain HTTP.
Affected Systems
Versions of Kuma prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7 that use a customized kumactl profile configured for HTTPS without specifying --ca-cert-file are impacted. The default local profile is not affected because it communicates over plain HTTP. Any environment running those versions in a position where an attacker can reach the TLS connection is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity vulnerability that can lead to loss of confidentiality and integrity but not necessarily availability. The EPSS score is < 1%, indicating the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector relies on a network adversary who can observe the traffic between kumactl and the control plane, which is plausible in shared or compromised network segments. Once the tokens are captured, the attacker can act as the authenticated user, signing requests, viewing data, or configuring the mesh. The default local profile uses plain HTTP and is not affected. Proper TLS verification mitigates the risk, and the issue is fixed in the specified releases.
OpenCVE Enrichment
Github GHSA